MEDIUM5.4
GHSA-j2fp-9wp5-mg66
Passbolt API is vulnerable to XSS in the url field on the password workspace grid and sidebar
Quick fix
GHSA-j2fp-9wp5-mg66 — passbolt/passbolt_api: upgrade to the fixed version with the command below.
composer require passbolt/passbolt_api:^1.6.5Details
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/passbolt/passbolt_api
Introduced in:
0Fixed in: 1.6.5Fix
composer require passbolt/passbolt_api:^1.6.5References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000442[ADVISORY]
- https://github.com/passbolt/passbolt_api/commit/f5eb93485a90195439e12aa8072f45ceb37b19c3[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/passbolt/passbolt_api/CVE-2017-1000442.yaml[WEB]
- https://github.com/passbolt/passbolt_api[PACKAGE]
- https://www.passbolt.com/incidents/20170914_xss_on_resource_urls[WEB]
- https://www.passbolt.com/release/notes#September[WEB]