CVE-2024-26140
Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser.
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- yetanalytics/lrs · yetanalytics/sql lrs
- Source
- security-advisories@github.com
References
- https://clojars.org/com.yetanalytics/lrs/versions/1.2.17Product, Release Notes
- https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621Patch
- https://github.com/yetanalytics/lrs/releases/tag/v1.2.17Release Notes
- https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46Vendor Advisory
- https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5Release Notes
- https://clojars.org/com.yetanalytics/lrs/versions/1.2.17Product, Release Notes
- https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621Patch
- https://github.com/yetanalytics/lrs/releases/tag/v1.2.17Release Notes
- https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46Vendor Advisory
- https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.