Trivial CSP Policy Bypass in Hush Line's Anonymous Tip Line Service
CVE-2024-38522
6.3MEDIUM
Key Information:
- Vendor
- Scidsg
- Status
- Hushline
- Vendor
- CVE Published:
- 28 June 2024
Summary
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the tips.hushline.app
website and bundled by default in this repository is trivial to bypass. This vulnerability has been patched in version 0.1.0.
Affected Version(s)
hushline < 0.1.0
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database