VulnerabilityModified
CVE-2022-41905
Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks.
MEDIUM 6.1EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set `dir_browser.enable = False` in the configuration.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wsgidav project/wsgidav
- Source
- security-advisories@github.com
References
- https://github.com/mar10/wsgidav/commit/e9606ab0f42f4c1a6611bc3c52de299b0aba7726Patch, Third Party Advisory
- https://github.com/mar10/wsgidav/security/advisories/GHSA-xx6g-jj35-pxjvMitigation, Third Party Advisory
- https://github.com/mar10/wsgidav/commit/e9606ab0f42f4c1a6611bc3c52de299b0aba7726Patch, Third Party Advisory
- https://github.com/mar10/wsgidav/security/advisories/GHSA-xx6g-jj35-pxjvMitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.