CVE-2021-3529
published 2021-06-02CVE-2021-3529: A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text…
PriorityP432high7.1CVSS 3.1
AVNACLPRNUIRSCCLILAL
EPSS
0.70%
49.4th percentile
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | noobaa-operator | < 5.7.0 | 5.7.0 |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
noobaa-core: Cross-site scripting vulnerability with noobaa management URL
vendor_redhat·2021-04-16·CVSS 7.1
CVE-2021-3529 [HIGH] CWE-79 noobaa-core: Cross-site scripting vulnerability with noobaa management URL
noobaa-core: Cross-site scripting vulnerability with noobaa management URL
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
A flaw was found in noobaa-core. This flaw results in the name of an arbitrary URL copied into an HTML document as plain text between tags, including a potential payload script. The input is echoed unmodified in the application response, resulting in arbitrary JavaScript being inje
GHSA
GHSA-cr32-cm8v-9pww: A flaw was found in noobaa-core in versions before 5
ghsa_unreviewed·2022-05-24
CVE-2021-3529 [CRITICAL] CWE-79 GHSA-cr32-cm8v-9pww: A flaw was found in noobaa-core in versions before 5
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
No detection rules found.
No public exploits indexed.
2021-06-02
Published