CVE-2024-55888

Source
https://cve.org/CVERecord?id=CVE-2024-55888
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55888.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-55888
Aliases
  • GHSA-m592-g8qv-hrqx
Published
2024-12-12T19:28:15.795Z
Modified
2026-04-10T05:18:37.338341Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
Content Security Policy appears to be missing in software and production setup
Details

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security headers. This could result in bypassing of cross-site scripting filters. Version 0.3.5 fixed the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55888.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1021"
    ]
}
References

Affected packages

Git / github.com/scidsg/hushline

Affected ranges

Type
GIT
Repo
https://github.com/scidsg/hushline
Events
Database specific
{
    "versions": [
        {
            "introduced": "0.1.0"
        },
        {
            "fixed": "0.3.5"
        }
    ]
}

Affected versions

v.*
v.0.1.12
v0.*
v0.1.0
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.13
v0.1.14
v0.1.15
v0.1.16
v0.1.17
v0.1.18
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9
v0.2.0
v0.2.1
v0.2.10
v0.2.11
v0.2.12
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55888.json"