CVE-2023-37272

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-37272
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37272.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-37272
Related
  • GHSA-qr44-gm3x-7hfc
Published
2023-07-13T23:15:10Z
Modified
2025-02-19T03:33:05.830855Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler (JS1). The vulnerability does not affect branch 2.x of JobScheduler (JS7) for releases after 2.1.0. The vulnerability is resolved with release 1.13.19.

References

Affected packages

Git / github.com/sos-berlin/joc-cockpit

Affected ranges

Type
GIT
Repo
https://github.com/sos-berlin/joc-cockpit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

joc-gui-1.*

joc-gui-1.11.0-RC1

v1.*

v1.11.0
v1.11.0-RC2
v1.11.0-RC3
v1.11.0-RC4
v1.11.0-RC5
v1.11.0-RC6
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.11.6
v1.11.7
v1.12.0
v1.12.1
v1.12.1-RC1
v1.12.2
v1.12.3
v1.12.4
v1.12.5
v1.12.6
v1.12.7
v1.12.8
v1.12.8-RC1
v1.12.9
v1.13.0
v1.13.1
v1.13.10
v1.13.11
v1.13.12
v1.13.13
v1.13.14
v1.13.15
v1.13.16
v1.13.17
v1.13.18
v1.13.2
v1.13.3
v1.13.4
v1.13.5
v1.13.6
v1.13.7
v1.13.8
v1.13.9