• 公告ID (KylinSec-SA-2024-1589)

摘要:

A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216743.

安全等级: Low

公告ID: KylinSec-SA-2024-1589

发布日期: 2024年5月27日

关联CVE: CVE-2022-4729  

  • 详细介绍

1. 漏洞描述

   

A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216743.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-4729 KY3.4-4A graphite2 Unaffected
CVE-2022-4729 KY3.4-5 graphite2 Unaffected
CVE-2022-4729 KY3.5.1 graphite2 Unaffected
CVE-2022-4729 KY3.5.2 graphite2 Unaffected
CVE-2022-4729 V6 graphite2 Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-1588 下一篇:KylinSec-SA-2024-1590