Skip to content

Web UI XSS via Rules injection

Moderate
st2stanley published GHSA-w277-gpp9-g249 Dec 5, 2022

Package

st2 (stackstorm)

Affected versions

<3.8.0

Patched versions

3.8.0
st2web (stackstorm)
<3.8.0
3.8.0

Description

Impact

Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or HTML that may be executed in Web UI for other logged in users.

Patches

Affected StackStorm versions: all prior v3.8.0.
The issue was fixed in StackStorm: v3.8.0.

References

Credits

This issue was discovered and reported to us by Mohamed Elgllad.

Severity

Moderate
5.4
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVE ID

CVE-2022-43706

Weaknesses