Vulnerability Description
Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Immuta | Immuta | 2.8.2 |
Related Weaknesses (CWE)
References
- https://labs.bishopfox.com/advisoriesExploitThird Party Advisory
- https://labs.bishopfox.com/advisories/immuta-version-2.8.2Release NotesThird Party Advisory
- https://www.immuta.com/Product
- https://labs.bishopfox.com/advisoriesExploitThird Party Advisory
- https://labs.bishopfox.com/advisories/immuta-version-2.8.2Release NotesThird Party Advisory
- https://www.immuta.com/Product
FAQ
What is CVE-2020-15952?
CVE-2020-15952 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta...
How severe is CVE-2020-15952?
CVE-2020-15952 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-15952?
Check the references section above for vendor advisories and patch information. Affected products include: Immuta Immuta.