指派后不支持 Apache SkyWalking Booster UI 中存在一个“网页生成过程中的输入未恰当中和(跨站脚本,XSS)”漏洞。 该问题影响 Apache SkyWalking UI 的 10.2.0 至 10.4.0 版本。 建议用户升级至 Horizon UI 1.0.0 以修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache SkyWalking | 10.2.0≤ 10.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache SkyWalking | 10.2.0 ~ 10.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80180 | Apache Allura: Stored XSS via markdown HTML processing | |
| CVE-2026-80181 | Apache Allura: Server-side request forgery | |
| CVE-2026-71216 | Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over clearte | |
| CVE-2026-81270 | Apache Allura: Information exposure via search | |
| CVE-2026-80190 | Apache Allura: Stored XSS via code repositories | |
| CVE-2026-52691 | Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module |
No comments yet