USN-8747-1: Beets vulnerability
Ubuntu released USN-8747-1 fixing a Beets web interface flaw that let attackers inject HTML or execute JavaScript via untrusted media metadata.
Ubuntu Security Notice USN-8747-1 addresses a vulnerability in the Beets music library manager, which incorrectly escaped untrusted media metadata in its web interface. An attacker could exploit this to inject arbitrary HTML or execute arbitrary JavaScript code in a user's browser. Updated packages are available for affected Ubuntu releases.
- Improper escaping of untrusted media metadata in Beets' web interface enables injection
- Could allow arbitrary HTML injection or JavaScript execution in a user's browser
- Fixed via updated Ubuntu packages in USN-8747-1
It was discovered that Beets incorrectly escaped untrusted media metadata in its web interface. An attacker could possibly use this issue to inject arbitrary HTML or execute arbitrary JavaScript code in a user's browser.
This source does not provide full text. Read it at ubuntu.com.