Vulnerabilities
Vulnerable Software
Stackstorm:  >> Stackstorm  >> 3.5.0  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or HTML that may be executed in Web UI for other logged in users.
CVSS Score
5.4
EPSS Score
0.006
Published
2022-12-05
In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.
CVSS Score
8.8
EPSS Score
0.026
Published
2021-12-15


Contact Us

Shodan ® - All rights reserved