CVE-2021-3914

Severity
6.1MEDIUM
EPSS
0.5%
top 34.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateAug 26

Description

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

🔴Vulnerability Details

3
OSV
SmallRye Health UI Cross-site Scripting vulnerability2022-08-26
GHSA
SmallRye Health UI Cross-site Scripting vulnerability2022-08-26
CVEList
CVE-2021-3914: It was found that the smallrye health metrics UI component did not properly sanitize some user inputs2022-08-25

📋Vendor Advisories

1
Red Hat
smallrye-health-ui: persistent cross-site scripting in endpoint2021-10-27