Description
Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
References
Product
https://cwe.mitre.org/data/definitions/79.html
Third Party Advisory
https://gainsec.com/2022/08/04/cve-2022-35142-cve-2022-35143-cve-2022-35144/
ExploitPatchThird Party Advisory
https://github.com/gilbitron/Raneto/releases
Release NotesThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
4.8 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2022-08-04T20:15:19.967
2 years agoLast modified
2022-08-11T14:10:24.767
2 years ago