VDB
Sign up
MEDIUM6.1

PYSEC-2022-43181

Details

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/codechecker-api

No fixed version published yet for codechecker-api (pip). Pin to a known-safe version or switch to an alternative.

References