Vulnerability Description
Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sal Project | Sal | <= 4.1.6 |
Related Weaknesses (CWE)
References
- https://github.com/salopensource/sal/commit/145bb72daf8460bdedbbc9fb708d346283e7PatchThird Party Advisory
- https://github.com/salopensource/sal/pull/405Third Party Advisory
- https://github.com/salopensource/sal/commit/145bb72daf8460bdedbbc9fb708d346283e7PatchThird Party Advisory
- https://github.com/salopensource/sal/pull/405Third Party Advisory
FAQ
What is CVE-2020-26205?
CVE-2020-26205 is a vulnerability with a CVSS score of 7.6 (HIGH). Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.
How severe is CVE-2020-26205?
CVE-2020-26205 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26205?
Check the references section above for vendor advisories and patch information. Affected products include: Sal Project Sal.