Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2392 | A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the `dangerouslySetInnerHTML` function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by injecting malicious scripts into the logs, which will be executed when a user views the logs-tab. |
Github GHSA |
GHSA-p9f2-jg9w-cx69 | Aim Stored Cross-site Scripting Vulnerability |
Tue, 20 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimstack
Aimstack aim |
|
| CPEs | cpe:2.3:a:aimstack:aim:3.19.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Aimstack
Aimstack aim |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T21:41:03.725Z
Reserved: 2024-07-08T17:56:48.272Z
Link: CVE-2024-6578
Updated: 2024-08-01T21:41:03.725Z
Status : Modified
Published: 2024-07-29T19:15:13.170
Modified: 2024-11-21T09:49:55.233
Link: CVE-2024-6578
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA