The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently accessed via web browser, these advisories are served and interpreted as HTML pages. Such uploaded advisories can contain JavaScript code that will execute within the browser context of users inspecting the advisory.
History

Tue, 22 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-13T00:00:00.000Z

Updated: 2025-04-22T15:10:58.311Z

Reserved: 2022-10-29T00:00:00.000Z

Link: CVE-2022-43996

cve-icon Vulnrichment

Updated: 2024-08-03T13:47:04.593Z

cve-icon NVD

Status : Modified

Published: 2022-12-13T22:15:10.247

Modified: 2025-04-22T15:16:04.453

Link: CVE-2022-43996

cve-icon Redhat

No data.