First published: Mon Jan 07 2013(Updated: )
A number of XSS flaws were reported in the Ganglia web frontend. These flaws are not currently public.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ganglia | <=3.5.5 | |
Ganglia | =2.1.0 | |
Ganglia | =2.1.1 | |
Ganglia | =2.1.2 | |
Ganglia | =2.1.3 | |
Ganglia | =2.1.5 | |
Ganglia | =2.1.6 | |
Ganglia | =2.1.7 | |
Ganglia | =2.1.8 | |
Ganglia | =2.2.0 | |
Ganglia | =3.3.0 | |
Ganglia | =3.3.1 | |
Ganglia | =3.4.1 | |
Ganglia | =3.4.2 | |
Ganglia | =3.5.0 | |
Ganglia | =3.5.1 | |
Ganglia | =3.5.2 | |
Ganglia | =3.5.3 | |
Ganglia | =3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-0275 is considered to be significant due to the potential for remote attackers to exploit the XSS vulnerabilities.
To fix CVE-2013-0275, upgrade to Ganglia Web version 3.5.6 or later, as these versions contain patches for the identified vulnerabilities.
CVE-2013-0275 is associated with multiple cross-site scripting (XSS) vulnerabilities that allow for arbitrary web script or HTML injection.
Versions of Ganglia Web prior to 3.5.6 and specific versions such as 2.1.0 through 3.5.5 are affected by CVE-2013-0275.
Yes, CVE-2013-0275 can be exploited remotely, allowing attackers to execute scripts in the context of the victim's browser.