Overview
- Description
- Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to cross-site scripting because the `XSSRequestWrapper::stripXSS` method can be bypassed. Versions 7.4.22, 8.0.9, and 8.1.0 contain patches for this issue. There are no known workarounds.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:eng:knowage:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C335213-2241-4023-A614-4E8A51E13BBB", "versionEndExcluding": "7.4.22", "versionStartIncluding": "6.1.0" }, { "criteria": "cpe:2.3:a:eng:knowage:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37F0CD95-EEF2-4217-A53D-6BF7F47106B9", "versionEndExcluding": "8.0.9", "versionStartIncluding": "8.0.0" } ], "operator": "OR" } ] } ]