Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1yOGo5LTVjajctY3YzOc4AA3ey

Reflected XSS Vulnerability in dpaste

Impact

A security vulnerability has been identified in the expires parameter of the dpaste API, allowing for a POST Reflected XSS attack. This vulnerability can be exploited by an attacker to execute arbitrary JavaScript code in the context of a user's browser, potentially leading to unauthorized access, data theft, or other malicious activities.

Patches

Workarounds

At this time, the recommended course of action is to apply the provided patch to the affected systems. No known workarounds have been identified, and applying the patch is the most effective way to remediate the vulnerability.

Permalink: https://github.com/advisories/GHSA-r8j9-5cj7-cv39
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yOGo5LTVjajctY3YzOc4AA3ey
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 6 months ago
Updated: 5 months ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-r8j9-5cj7-cv39, CVE-2023-49277
References: Repository: https://github.com/DarrenOfficial/dpaste
Blast Radius: 3.7

Affected Packages

pypi:Dpaste
Dependent packages: 0
Dependent repositories: 4
Downloads: 52 last month
Affected Version Ranges: < 3.8
Fixed in: 3.8
All affected versions: 3.3.1
All unaffected versions: