在 Amundsen 前端 4.3.0 及之前版本中, 组件使用 渲染表、仪表板和特征的描述信息,但未对 HTML 进行净化(sanitization)。攻击者可以通过元数据服务或 Elasticsearch,将带有 事件处理函数的 元素等恶意标记注入到描述信息中,从而在查看搜索结果的所有用户的浏览器中执行 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| amundsen-io | amundsen-frontend | 0 ~ 4.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet