Skip to content

XSS vulnerability caused by internal media proxy

Moderate
DIYgod published GHSA-2wqw-hr4f-xrhh Mar 5, 2024

Package

No package listed

Affected versions

>= cbbd829, < 4d3e5d7

Patched versions

4d3e5d7

Description

Impact

When the specially crafted image is supplied to the internal media proxy, it proxies the image without handling XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code.

Users who access the deliberately constructed URL are affected.

Patches

This vulnerability was fixed in version 4d3e5d7. Please upgrade to this or a later version.

Workarounds

No.

Severity

Moderate

CVE ID

CVE-2024-27926

Weaknesses

No CWEs

Credits