CVE-2020-8031: obs: Stored XSS
Published Feb 11, 2021
·Updated
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.
Affected Software
1 affected component
openSUSE Open Build Service<2.10.8
Event History
Feb 11, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-8031.
2
What is the severity of CVE-2020-8031?
The severity of CVE-2020-8031 is medium with a CVSS score of 5.4.
3
How does CVE-2020-8031 impact confidentiality and integrity?
CVE-2020-8031 allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity.
4
Which software is affected by CVE-2020-8031?
Open Build Service versions prior to 2.10.8 are affected by CVE-2020-8031.
5
Is there a fix available for CVE-2020-8031?
Yes, updating to Open Build Service version 2.10.8 or later fixes CVE-2020-8031.