JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler (JS1). The vulnerability does not affect branch 2.x of JobScheduler (JS7) for releases after 2.1.0. The vulnerability is resolved with release 1.13.19.
History

Mon, 21 Oct 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-07-13T22:28:34.238Z

Updated: 2024-10-21T21:09:36.457Z

Reserved: 2023-06-29T19:35:26.440Z

Link: CVE-2023-37272

cve-icon Vulnrichment

Updated: 2024-08-02T17:09:34.055Z

cve-icon NVD

Status : Modified

Published: 2023-07-13T23:15:10.677

Modified: 2024-11-21T08:11:22.053

Link: CVE-2023-37272

cve-icon Redhat

No data.