CVE-2022-41905
Summary
| CVE | CVE-2022-41905 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-11 21:15:00 UTC |
| Updated | 2022-11-16 18:10:00 UTC |
| Description | WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set `dir_browser.enable = False` in the configuration. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wsgidav Project | Wsgidav | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled · Advisory · mar10/wsgidav · GitHub | CONFIRM | github.com | |
| Merge pull request from GHSA-xx6g-jj35-pxjv · mar10/wsgidav@e9606ab · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.