VulnerabilityModified
CVE-2021-3914
An attacker could use this flaw to conduct cross-site scripting attacks.
MEDIUM 6.1EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- redhat/build of quarkus · redhat/openshift application runtimes · redhat/smallrye health
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2021-3914Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2018015Issue Tracking, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2021-3914Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2018015Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.