CVE-2024-26140
Last modified
CVE-2024-26140 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yetanalytics | Lrs | < 1.2.17 |
| Yetanalytics | Sql Lrs | < 0.7.5 |
References
- https://clojars.org/com.yetanalytics/lrs/versions/1.2.17Product, Release Notes
- https://clojars.org/com.yetanalytics/lrs/versions/1.2.17Product, Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-26140?
How severe is CVE-2024-26140?
How do I fix CVE-2024-26140?
Are you affected by CVE-2024-26140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
