QID 994864
Date Published: 2023-08-17
QID 994864: Python (Pip) Security Update for scancodeio (GHSA-6xcx-gx7r-rccj)
In the /license/ endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a detailed license view that does not exist.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6xcx-gx7r-rccj for updates and patch information.
Vendor References
- GHSA-6xcx-gx7r-rccj -
github.com/advisories/GHSA-6xcx-gx7r-rccj
CVEs related to QID 994864
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6xcx-gx7r-rccj | scancodeio |
|