CVE-2022-41139: XSS
Published Oct 17, 2022
·Updated
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.
Affected Software
1 affected component
MITRE CALDERA<4.1.0
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-41139.
2
What is the severity of CVE-2022-41139?
The severity of CVE-2022-41139 is medium.
3
How can the stored XSS vulnerability be exploited in MITRE CALDERA 4.1.0?
The stored XSS vulnerability in MITRE CALDERA 4.1.0 can be exploited via the app.contact.gist field, allowing execution of arbitrary commands on agents.
4
What software version is affected by CVE-2022-41139?
MITRE CALDERA version 4.1.0 is affected by CVE-2022-41139.
5
Is there a fix available for CVE-2022-41139?
Yes, it is recommended to upgrade to a version higher than 4.1.0 to mitigate the vulnerability.