GHSA-2pg6-vw9c-qhjv

Source
https://github.com/advisories/GHSA-2pg6-vw9c-qhjv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-2pg6-vw9c-qhjv/GHSA-2pg6-vw9c-qhjv.json
Aliases
  • CVE-2024-33670
Published
2024-04-26T03:30:29Z
Modified
2024-04-26T17:12:07.240684Z
Details

Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.

References

Affected packages

Packagist / passbolt/passbolt_api

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
4.6.2

Affected versions

v1.*

v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.0.10
v1.0.11
v1.0.12
v1.0.13
v1.0.14
v1.1.0
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.9
v1.6.10

v2.*

v2.0.0-rc1
v2.0.0-rc2
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.7
v2.0.8
v2.1.0
v2.1.1
v2.2.0
v2.3.0
v2.4
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.7.2
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.5
v2.9.0
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.13.0-RC1
v2.13.0
v2.13.1
v2.13.5
v2.14.0

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.2.0
v3.2.1
v3.2.2
v3.3.0
v3.3.1
v3.4.0
v3.5.0
v3.6.0
v3.7.0
v3.7.1
v3.7.2
v3.7.3
v3.8.0
v3.8.1
v3.8.3
v3.9.0
v3.10.0
v3.11.0
v3.11.1
v3.12.0-rc.1
v3.12.0-rc.2
v3.12.0
v3.12.2-rc.1
v3.12.2-rc.5
v3.12.2

v4.*

v4.0.0-rc.2
v4.0.0-rc.3
v4.0.0-rc.4
v4.0.0-rc.5
v4.0.0
v4.0.1-rc.1
v4.0.1
v4.0.2-rc.1
v4.0.2
v4.1.0-rc.2
v4.1.0-rc.3
v4.1.0
v4.1.1-rc.1
v4.1.1-rc.2
v4.1.1
v4.1.2-rc.2
v4.1.2
v4.2.0-rc.1
v4.2.0-rc.2
v4.2.0
v4.3.0-rc.1
v4.3.0
v4.4.0-rc.1
v4.4.0
v4.4.1
v4.4.2
v4.5.0-rc.1
v4.5.0
v4.5.2
v4.6.0-rc.1
v4.6.0-rc.2
v4.6.0
v4.6.1