CVE-2024-29217
published 2024-04-21CVE-2024-29217: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before…
PriorityP420medium4.6CVSS 3.1
AVNACLPRLUIRSUCNILAL
EPSS
0.97%
57.6th percentile
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.
XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.
Users are recommended to upgrade to version [1.3.0], which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | answer | < 1.3.0 | 1.3.0 |
| apache_software_foundation | apache_answer | < 1.3.0 | 1.3.0 |
| authlib | authlib | >= 0 < 1.3.1 | 1.3.1 |
| github.com | apache_incubator-answer | >= 0 < 1.3.0 | 1.3.0 |
| python-jose_project | python-jose | >= 0 < 3.4.0 | 3.4.0 |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
ghsa7.5HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Authlib has algorithm confusion with asymmetric public keys
ghsa·2024-06-09·CVSS 7.5
CVE-2024-37568 [HIGH] CWE-284 Authlib has algorithm confusion with asymmetric public keys
Authlib has algorithm confusion with asymmetric public keys
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
OSV
XSS vulnerability via personal website in github.com/apache/incubator-answer
osv·2024-04-26
CVE-2024-29217 XSS vulnerability via personal website in github.com/apache/incubator-answer
XSS vulnerability via personal website in github.com/apache/incubator-answer
XSS vulnerability via personal website in github.com/apache/incubator-answer
GHSA
python-jose algorithm confusion with OpenSSH ECDSA keys
ghsa·2024-04-26·CVSS 7.5
CVE-2024-33663 [HIGH] CWE-327 python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
OSV
Apache Answer: XSS vulnerability when changing personal website
osv·2024-04-21
CVE-2024-29217 [MEDIUM] Apache Answer: XSS vulnerability when changing personal website
Apache Answer: XSS vulnerability when changing personal website
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.
XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.
Users are recommended to upgrade to version [1.3.0], which fixes the issue.
GHSA
Apache Answer: XSS vulnerability when changing personal website
ghsa·2024-04-21
CVE-2024-29217 [MEDIUM] CWE-79 Apache Answer: XSS vulnerability when changing personal website
Apache Answer: XSS vulnerability when changing personal website
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.
XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.
Users are recommended to upgrade to version [1.3.0], which fixes the issue.
Red Hat
python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
vendor_redhat·2024-04-26·CVSS 7.4
CVE-2024-33663 [HIGH] python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Package: python-jose (Red Hat Ansible Automation Platform 2) - Not affected
No detection rules found.
No public exploits indexed.
2024-04-21
Published