CVE-2024-9526

There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d
References
Link Resource
https://github.com/kubeflow/pipelines/pull/10315 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:kubeflow:pipelines:*:*:*:*:*:*:*:*

History

23 Jul 2025, 19:42

Type Values Removed Values Added
First Time Kubeflow
Kubeflow pipelines
References () https://github.com/kubeflow/pipelines/pull/10315 - () https://github.com/kubeflow/pipelines/pull/10315 - Issue Tracking, Patch
CPE cpe:2.3:a:kubeflow:pipelines:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de XSS almacenada en la interfaz web de Kubeflow Pipeline View. La interfaz web de Kubeflow permite crear nuevas canalizaciones. Al crear una nueva canalización, es posible agregar una descripción. El campo de descripción permite etiquetas HTML, que no se filtran correctamente. Esto genera un XSS almacenado. Recomendamos actualizar la versión anterior a el commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d

18 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 14:15

Updated : 2025-07-23 19:42


NVD link : CVE-2024-9526

Mitre link : CVE-2024-9526

CVE.ORG link : CVE-2024-9526


JSON object : View

Products Affected

kubeflow

  • pipelines
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')