Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54482 | LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality |
Github GHSA |
GHSA-9cwv-pxcr-hfjc | LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfedge
Lfedge ekuiper |
|
| CPEs | cpe:2.3:a:lfedge:ekuiper:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfedge
Lfedge ekuiper |
Wed, 14 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Configuration key `Name` (`confKey`) parameter. After this setup, when any user with access to this service (e.g. admin) tries to delete this key, a payload acts in the victim's browser. Version 2.1.0 fixes the issue. | |
| Title | Stored XSS in Configuration Key Functionality | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-14T13:21:31.315Z
Reserved: 2024-11-06T19:00:26.394Z
Link: CVE-2024-52290
Updated: 2025-05-14T13:21:21.859Z
Status : Analyzed
Published: 2025-05-14T08:15:33.250
Modified: 2025-07-11T16:20:52.177
Link: CVE-2024-52290
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA