Stored XSS in Kubeflow Pipeline View
CVE-2024-9526

5.4MEDIUM

Key Information:

Vendor

Kubeflow

Vendor
CVE Published:
18 November 2024

What is CVE-2024-9526?

A stored XSS vulnerability exists within the Kubeflow Pipeline View web UI, which permits the injection of malicious scripts through the description field when creating new pipelines. The description field does not properly filter HTML tags, allowing attackers to embed harmful scripts that execute in the context of other users accessing the affected web application. It is critical to apply the recommended upgrades beyond commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d to mitigate potential exploitation.

Affected Version(s)

Kubeflow Pipeline View 0 < 930c35f1c543998e60e8d648ce93185c9b5dbe8d

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Philipp Schneider
.