Bug 1216925 (CVE-2023-5950) - VUL-0: CVE-2023-5950: velociraptor: Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability
Summary: VUL-0: CVE-2023-5950: velociraptor: Rapid7 Velociraptor versions prior to 0.7...
Status: RESOLVED FIXED
Alias: CVE-2023-5950
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/384237/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-5950:8.6:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-07 04:15 UTC by SMASH SMASH
Modified: 2024-02-15 04:29 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-11-07 04:15:49 UTC
Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site
scripting vulnerability. This vulnerability allows attackers to inject JS into
the error path, potentially leading to unauthorized execution of scripts within
a user's web browser. This vulnerability is fixed in version 0.7.0-04 and
a patch is available to download. Patches are also available for version 0.6.9
(0.6.9-1).



References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5950
Comment 3 Jeff Mahoney 2024-02-02 19:00:49 UTC
security:sensor and Factory have had 0.7.0-4 since mid-December.