VulnerabilityModified
CVE-2020-9299
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter.
MEDIUM 5.4EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- netflix/dispatch
- Source
- security-report@netflix.com
References
- https://github.com/Netflix/dispatch/releases/tag/v20201106Third Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.mdThird Party Advisory
- https://github.com/Netflix/dispatch/releases/tag/v20201106Third Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.mdThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.