Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13bWZjLWc4NnAtZmp2cs4AAzhX
go package pydio cells vulnerable to cross-site scripting
A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. This issue affects some unknown processing of the component Chat. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-230213 was assigned to this vulnerability.
Permalink: https://github.com/advisories/GHSA-wmfc-g86p-fjvrJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13bWZjLWc4NnAtZmp2cs4AAzhX
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 11 months ago
Updated: 6 months ago
CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Identifiers: GHSA-wmfc-g86p-fjvr, CVE-2023-2981
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-2981
- https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421
- https://vuldb.com/?ctiid.230213
- https://vuldb.com/?id.230213
- https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be
- https://github.com/advisories/GHSA-wmfc-g86p-fjvr
Affected Packages
go:github.com/pydio/cells
Dependent packages: 2Dependent repositories: 4
Downloads:
Affected Version Ranges: < 4.2.1
Fixed in: 4.2.1
All affected versions: 0.9.0, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.4.0, 1.4.1, 1.5.0, 1.5.2, 1.5.3, 1.6.0, 1.6.1, 1.6.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.11, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.2.9, 2.2.11, 2.2.12, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.9
All unaffected versions: