CVE-2021-42648: XSS
Published May 11, 2022
·Updated
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.
Affected Software
1 affected component
Coder Code-Server<3.12.0
Remediation
Patch Available
Event History
May 11, 2022
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-42648?
CVE-2021-42648 is considered a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2021-42648?
To fix CVE-2021-42648, update Coder Code-Server to version 3.12.0 or later.
3
What impact does CVE-2021-42648 have on my application?
CVE-2021-42648 allows attackers to execute arbitrary code through crafted URLs, posing significant security risks.
4
Is CVE-2021-42648 easy to exploit?
Yes, CVE-2021-42648 can be exploited easily by sending a malicious URL to a victim.
5
What versions are affected by CVE-2021-42648?
CVE-2021-42648 affects all versions of Coder Code-Server prior to 3.12.0.