CVE-2024-9526

There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-11-18 14:15

Updated : 2024-11-18 17:11


NVD link : CVE-2024-9526

Mitre link : CVE-2024-9526

CVE.ORG link : CVE-2024-9526


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')