CVE-2022-35630: Unsafe HTML Injection in Artifact Collection Report
Published Jul 29, 2022
·Updated
A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.
Affected Software
1 affected component
Rapid7 Velociraptor<0.6.5-2
Remediation
Event History
Jul 29, 2022
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-35630?
CVE-2022-35630 is a cross-site scripting (XSS) vulnerability in the collection report generation functionality in Velociraptor.
2
How can malicious clients exploit CVE-2022-35630?
Malicious clients can exploit CVE-2022-35630 by injecting JavaScript code into the static HTML file during the collection report generation process.
3
What is the severity of CVE-2022-35630?
The severity of CVE-2022-35630 is medium with a CVSS score of 6.1.
4
Which version of Velociraptor is affected by CVE-2022-35630?
Velociraptor versions up to and excluding 0.6.5-2 are affected by CVE-2022-35630.
5
How was CVE-2022-35630 resolved?
CVE-2022-35630 was resolved in Velociraptor 0.6.5-2.