CVE Feed

    Dashboard / CVE / CVE-2024-42346

    CVE-2024-42346

    Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:Sep 20, 2024
    Last Modified:Aug 15, 2025
    EPS:Sep 20, 2024
    EPSS Score:0.03098
    CVSS Score:7.6

    Affected Products

    Vendor
    Galaxyproject
    Product
    Galaxy

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High