CVE-2021-44217: XSS
In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44217?
The severity of CVE-2021-44217 is medium with a CVSS score of 6.1.
How does CVE-2021-44217 affect Ericsson CodeChecker?
CVE-2021-44217 affects Ericsson CodeChecker versions up to and including 6.18.0.
What is the vulnerability in Ericsson CodeChecker identified as CVE-2021-44217?
CVE-2021-44217 is a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer in Ericsson CodeChecker.
How can remote attackers exploit CVE-2021-44217?
Remote attackers can exploit CVE-2021-44217 by injecting arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.
Is there a fix available for CVE-2021-44217?
Yes, the fix for CVE-2021-44217 can be found in the latest version of Ericsson CodeChecker.