CVE-2024-6585

Source
https://cve.org/CVERecord?id=CVE-2024-6585
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6585.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6585
Aliases
  • GHSA-6529-6jv3-66q2
Published
2024-08-30T22:17:28Z
Modified
2026-08-12T03:51:34Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.

Database specific
{
    "cna_assigner": "Mandiant",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6585.json"
}
References

Affected packages

Git / github.com/lightdash/lightdash

Affected ranges

Type
GIT
Repo
https://github.com/lightdash/lightdash
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.1024.6"
        },
        {
            "fixed": "0.1042.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1024.10
0.1024.6
0.1024.7
0.1024.8
0.1024.9
0.1025.0
0.1025.1
0.1025.2
0.1025.3
0.1025.4
0.1025.5
0.1025.6
0.1025.7
0.1026.0
0.1026.1
0.1026.2
0.1026.3
0.1026.4
0.1027.0
0.1027.1
0.1027.2
0.1027.3
0.1027.4
0.1028.0
0.1028.1
0.1028.2
0.1029.0
0.1029.1
0.1030.0
0.1030.1
0.1030.2
0.1030.3
0.1030.4
0.1030.5
0.1030.6
0.1030.7
0.1030.8
0.1031.0
0.1031.1
0.1032.0
0.1033.0
0.1034.0
0.1034.1
0.1035.0
0.1035.1
0.1035.2
0.1036.0
0.1036.1
0.1036.2
0.1036.3
0.1036.4
0.1036.5
0.1036.6
0.1037.0
0.1038.0
0.1038.1
0.1038.2
0.1038.3
0.1038.4
0.1038.5
0.1039.0
0.1039.1
0.1039.2
0.1040.0
0.1040.1
0.1040.2
0.1041.0
0.1041.1
0.1041.2
0.1042.0
0.1042.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6585.json"