Trivial CSP Policy Bypass in Hush Line's Anonymous Tip Line Service
CVE-2024-38522
6.3MEDIUM
Key Information
- Vendor
- Scidsg
- Status
- Hushline
- Vendor
- CVE Published:
- 28 June 2024
Summary
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in this repository is trivial to bypass. This vulnerability has been patched in version 0.1.0.
Affected Version(s)
hushline = < 0.1.0
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database