CVE-2021-44217

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:*

History

24 Jan 2022, 18:14

Type Values Removed Values Added
References (MISC) https://user-images.githubusercontent.com/9525971/142965091-e118b012-a7fc-4c2f-ad0c-80aeed6f7ec9.png - (MISC) https://user-images.githubusercontent.com/9525971/142965091-e118b012-a7fc-4c2f-ad0c-80aeed6f7ec9.png - Third Party Advisory
References (MISC) https://github.com/Ericsson/codechecker/releases - (MISC) https://github.com/Ericsson/codechecker/releases - Release Notes, Third Party Advisory
References (MISC) https://github.com/Ericsson/codechecker/pull/3549 - (MISC) https://github.com/Ericsson/codechecker/pull/3549 - Patch, Third Party Advisory
References (MISC) https://codechecker-demo.eastus.cloudapp.azure.com/ - (MISC) https://codechecker-demo.eastus.cloudapp.azure.com/ - Permissions Required
References (MISC) https://github.com/Hyperkopite/CVE-2021-44217/blob/main/README.md - (MISC) https://github.com/Hyperkopite/CVE-2021-44217/blob/main/README.md - Exploit, Third Party Advisory
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:*

18 Jan 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-18 15:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-44217

Mitre link : CVE-2021-44217

CVE.ORG link : CVE-2021-44217


JSON object : View

Products Affected

ericsson

  • codechecker
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')