Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Koji: escape html tag characters in the query string
Vulnerability Description
A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
对输出编码和转义不恰当
Vulnerability Title
Koji 安全漏洞
Vulnerability Description
Koji是Koji开源的一套RPM构建系统。 Koji存在安全漏洞,该漏洞源于没有对用户的输入进行清理。
CVSS Information
N/A
Vulnerability Type
N/A