Skip to content

Two reflected Cross-Site-scripting vulnerabilities

Moderate
puiterwijk published GHSA-f7qc-frqp-4wrx Nov 30, 2020

Package

bodhi

Affected versions

<5.6.1

Patched versions

5.6.1

Description

Impact

A reflected cross-site scripting attack allowed an attacker to get a user's browser to inject malicious javascript code into the Bodhi page.

Patches

Versions 5.6.1 and up contain patches.

For more information

If you have any questions or comments about this advisory:

Reported by

We would like to thank @hexdefined for the report of this vulnerability.

Severity

Moderate

CVE ID

CVE-2020-15855

Weaknesses

No CWEs