First published: Thu Feb 11 2021(Updated: )
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <2.10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-8031.
The severity of CVE-2020-8031 is medium with a CVSS score of 5.4.
CVE-2020-8031 allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity.
Open Build Service versions prior to 2.10.8 are affected by CVE-2020-8031.
Yes, updating to Open Build Service version 2.10.8 or later fixes CVE-2020-8031.