CVE-2026-90772
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
13/09/2026
Última modificación:
24/09/2026
Descripción
*** Pendiente de traducción *** Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Impacto
Puntuación base 4.0
8.30
Gravedad 4.0
ALTA
Puntuación base 3.x
7.60
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/amundsen-io/amundsen
- https://github.com/amundsen-io/amundsen/blob/frontend-4.3.0/frontend/amundsen_application/static/js/components/ResourceListItem/TableListItem/index.tsx
- https://github.com/amundsen-io/amundsen/issues/2362
- https://www.vulncheck.com/advisories/amundsen-frontend-through-4.3.0-stored-xss-via-description
- https://github.com/amundsen-io/amundsen/issues/2362


