VDB

GCVE-VVD-MAGEIA-2023-61

GCVE-VVD-MAGEIA-2023-61
Advisory Published
Vulnetix · Advisory published September 3, 2023
When the host header does not match a configured host twisted.web.vhost.NameVirtualHost will return a NoResource resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. (CVE-2022-39348)

Affected Products

VendorProductVersionsPlatforms
Mageiadarktable0 (affected), 4.4.2-1.mga9 (unaffected)
Mageiapython-twisted0 (affected), 22.10.0-1.mga8 (unaffected), 0 (affected), 22.10.0-1.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›