[MAVEN:GHSA-7RW2-3HHP-RC46] Cross-site Scripting Vulnerability in Statement Browser

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Impact

A maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser.

Patches

The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS.

Workarounds

No workarounds exist, we recommend upgrading to version 1.2.17 of the library or version 0.7.5 of SQL LRS immediately.

References

Package Affected Version
pkg:maven/com.yetanalytics/lrs < 1.2.17
Package Fixed Version
pkg:maven/com.yetanalytics/lrs = 1.2.17
ID
MAVEN:GHSA-7RW2-3HHP-RC46
Severity
moderate
URL
https://github.com/advisories/GHSA-7rw2-3hhp-rc46
Published
2024-02-21T00:24:56
(7 months ago)
Modified
2024-02-21T00:34:15
(7 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.yetanalytics/lrs com.yetanalytics lrs < 1.2.17
Fixed pkg:maven/com.yetanalytics/lrs com.yetanalytics lrs = 1.2.17
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...