CVE-2021-44217

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-44217
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44217.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-44217
Aliases
Withdrawn
2024-05-08T06:52:20.811265Z
Published
2022-01-18T15:15:08Z
Modified
2023-11-28T22:57:58.581105Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

References

Affected packages

Git / github.com/ericsson/codechecker

Affected ranges

Type
GIT
Repo
https://github.com/ericsson/codechecker
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

5.*

5.2

v4.*

v4.0

v5.*

v5.0
v5.1
v5.10
v5.3
v5.4
v5.5
v5.6
v5.7
v5.7.1
v5.8
v5.9

v6.*

v6.0
v6.0.1
v6.1
v6.1.1
v6.10.0
v6.12.0
v6.13.0
v6.14.0
v6.15.0
v6.16.0
v6.17.0
v6.18.0
v6.2
v6.2.1
v6.3
v6.4
v6.5
v6.5.1
v6.6.0
v6.7.0
v6.7.1
v6.8.0
v6.8.1
v6.9.0
v6.9.1