QID 997160
Date Published: 2024-02-09
QID 997160: GO (Go) Security Update for github.com/rancher/norman (GHSA-r8f4-hv23-6qp6)
A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r8f4-hv23-6qp6 for updates and patch information.
Vendor References
- GHSA-r8f4-hv23-6qp6 -
github.com/advisories/GHSA-r8f4-hv23-6qp6
CVEs related to QID 997160
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r8f4-hv23-6qp6 | github.com/rancher/norman |
|