ZeroHour

CVE-2021-3914

CVSS 3.1
6.1 medium
EPSS
<1%p42
Published
()
Modified
Description

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.

Vendors
redhat
Products
build of quarkus, openshift application runtimes, smallrye health
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.