First published: Tue Apr 11 2023(Updated: )
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenWrt OpenWrt | =22.03.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24182 is medium with a CVSS score of 5.4.
CVE-2023-24182 is a stored cross-site scripting (XSS) vulnerability in LuCI openwrt-22.03 branch git-22.361.69894-438c598 via the /system/sshkeys.js component.
CVE-2023-24182 affects OpenWrt version 22.03.3 running LuCI openwrt-22.03 branch git-22.361.69894-438c598.
Yes, there have been commits made to the OpenWrt LuCI repository to address the vulnerability. Updating to the latest version of LuCI should fix the issue.
you can find more information about CVE-2023-24182 on the GitHub security advisory page (https://github.com/ABB-EL/external-vulnerability-disclosures/security/advisories/GHSA-7vqh-2r8q-rjg2) and the OpenWrt LuCI repository commits (https://github.com/openwrt/luci/commit/0186d7eae0e123a409e9919a83fdfecc7945c984, https://github.com/openwrt/luci/commit/588381e2111079265cc3b20af33507052f1b58cb).