CVE-2024-53257 PUBLISHED CVSS 4.900000095367432 MEDIUM

Vitess allows HTML injection in /debug/querylogz & /debug/env

EPSS 0.03% · 8.8th percentile

Risk Scores

CVSS v3.1
4.900000095367432
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.03%
8.8th percentile

Affected Products

VendorProductVersions
vitessiovitess0, 19.0.9, 20.0.5
vitessiovitess>= 0.21.0-rc1, < 21.0.1, >= 0.20.0-rc1, < 20.0.4, < 19.0.8
vitess.iovitess0.21.0-rc1, 0.20.0-rc1, 0

Timeline

References

Open in Interactive Console →