CVE-2020-9299
Last modified
CVE-2020-9299 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netflix | Dispatch | < 20201106 |
References
- https://github.com/Netflix/dispatch/releases/tag/v20201106Third Party Advisory
- https://github.com/Netflix/dispatch/releases/tag/v20201106Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9299?
How severe is CVE-2020-9299?
How do I fix CVE-2020-9299?
Are you affected by CVE-2020-9299?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
