Weave GitOps Enterprise before 0.9.0-rc.5 has a cross...
Moderate severity
Unreviewed
Published
Sep 2, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Sep 1, 2022
Published to the GitHub Advisory Database
Sep 2, 2022
Last updated
Jan 28, 2023
Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise UI via a GitopsCluster dashboard link. An annotation can be added to a GitopsCluster custom resource.
References