CVE-2021-31330
Summary
| CVE | CVE-2021-31330 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-11 18:15:00 UTC |
| Updated | 2022-05-20 14:19:00 UTC |
| Description | A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Reviewboard | Review Board | 3.0.20 | All | All | All |
| Application | Reviewboard | Review Board | 4.0 | beta1 | All | All |
| Application | Reviewboard | Review Board | 4.0 | beta2 | All | All |
| Application | Reviewboard | Review Board | 4.0 | rc1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Review Board XSS Discovered – Schmidt Happens – InfoSec Blog | MISC | mattschmidt.net | |
| Review Board 3.0.21 Release Notes | Documentation | Review Board | MISC | www.reviewboard.org | |
| Review Board 4.0 RC 2 Release Notes | Documentation | Review Board | MISC | www.reviewboard.org | |
| Review Board 3.0.21 and 4.0 RC 2: Security Fixes, Bug Fixes, and Docker | News | Review Board | MISC | www.reviewboard.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.