CVE-2022-39295: Improper Neutralization of Alternate XSS Syntax in Knowage-Server
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to cross-site scripting because the XSSRequestWrapper::stripXSS method can be bypassed. Versions 7.4.22, 8.0.9, and 8.1.0 contain patches for this issue. There are no known workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39295?
The severity of CVE-2022-39295 is classified as medium due to the potential for cross-site scripting attacks.
How do I fix CVE-2022-39295?
To fix CVE-2022-39295, upgrade to Knowage versions 7.4.22, 8.0.9, or 8.1.0 or later.
What software is affected by CVE-2022-39295?
CVE-2022-39295 affects Knowage versions from the 6.x branch up to but not including 7.4.22 and 8.0.0 up to but not including 8.0.9.
What type of vulnerability is CVE-2022-39295?
CVE-2022-39295 is a cross-site scripting (XSS) vulnerability.
Who is the vendor for the software affected by CVE-2022-39295?
The vendor for the software affected by CVE-2022-39295 is Eng.