Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50317 | There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d |
| Link | Providers |
|---|---|
| https://github.com/kubeflow/pipelines/pull/10315 |
|
Wed, 23 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubeflow pipelines
|
|
| CPEs | cpe:2.3:a:kubeflow:pipelines:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kubeflow pipelines
|
|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubeflow
Kubeflow kubeflow W Pipeline View |
|
| CPEs | cpe:2.3:a:kubeflow:kubeflow_w_pipeline_view:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kubeflow
Kubeflow kubeflow W Pipeline View |
|
| Metrics |
ssvc
|
Mon, 18 Nov 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d | |
| Title | Stored XSS in Kubeflow Pipeline View | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-11-21T10:24:31.751Z
Reserved: 2024-10-04T12:51:28.581Z
Link: CVE-2024-9526
Updated: 2024-11-18T14:12:04.096Z
Status : Analyzed
Published: 2024-11-18T14:15:05.873
Modified: 2025-07-23T19:42:10.907
Link: CVE-2024-9526
No data.
OpenCVE Enrichment
No data.
EUVD