PT-2017-8755 · Openstack · Openstack Puppet Module

CVE-2016-5737

·

Publicado

2017-01-12

·

Atualizado

2026-05-13

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Openstack Puppet module for Gerrit (affected versions not specified)
Description The issue is related to the Gerrit configuration in the Openstack Puppet module, where text/html is improperly marked as a safe mimetype. This could potentially allow remote attackers to conduct cross-site scripting (XSS) attacks by crafting a review.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5737

Produtos afetados

Openstack Puppet Module