VDB

CVE-2024-53257

CVE-2024-53257 PUBLISHED CVSS 4.900000095367432 MEDIUM

Vitess allows HTML injection in /debug/querylogz & /debug/env

EPSS 0.06% · 18.3th percentile

Risk Scores

CVSS 3.1
4.900000095367432
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.06%
18.3th percentile

Affected Products

VendorProductVersions
vitessiovitess0, 19.0.9, 20.0.5
vitessiovitess>= 0.21.0-rc1, < 21.0.1, >= 0.20.0-rc1, < 20.0.4, < 19.0.8
vitess.iovitess0.21.0-rc1, 0.20.0-rc1, 0

Timeline

  • Jan 21, 1970 Security Advisory
  • Dec 3, 2024 CVE Published
  • Dec 3, 2024 PoC Published
  • Dec 3, 2024 PoC Published
  • Dec 4, 2024 EPSS Score
  • Dec 16, 2024 CVE Updated
  • Dec 21, 2024 EPSS Score
  • Jan 7, 2025 EPSS Score
  • Jan 24, 2025 EPSS Score
  • Feb 10, 2025 EPSS Score
  • Feb 27, 2025 EPSS Score
  • Mar 3, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›