CVE-2021-3529
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
02/06/2021
Last modified:
15/06/2021
Description
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:noobaa-operator:*:*:*:*:*:*:*:* | 5.7.0 (excluding) | |
| cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



