There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.
References
Link | Resource |
---|---|
https://github.com/Netflix/dispatch/releases/tag/v20201106 | Third Party Advisory |
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.md | Third Party Advisory |
Configurations
Information
Published : 2020-11-09 07:15
Updated : 2020-11-17 12:19
NVD link : CVE-2020-9299
Mitre link : CVE-2020-9299
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
netflix
- dispatch