SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-15951

Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application.

MEDIUM 6.1EPSS 0.97%

Does this matter?

Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.

Description

Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.97% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
immuta/immuta
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.