GHSA-j2fp-9wp5-mg66
Dashboard / Vulnerabilities / GHSA-j2fp-9wp5-mg66
Summary: Passbolt API is vulnerable to XSS in the url field on the password workspace grid and sidebar
Details: Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000442, https://github.com/passbolt/passbolt_api/commit/f5eb93485a90195439e12aa8072f45ceb37b19c3, https://github.com/FriendsOfPHP/security-advisories/blob/master/passbolt/passbolt_api/CVE-2017-1000442.yaml, https://github.com/passbolt/passbolt_api, https://www.passbolt.com/incidents/20170914_xss_on_resource_urls, https://www.passbolt.com/release/notes#September
Affected packages
Package
Name: passbolt/passbolt_api
Purl: pkg:composer/passbolt/passbolt_api
Affected ranges
Type: ECOSYSTEM
Events:
