Vulnerability Description
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moveit | Moveit | 1.1.11 |
Related Weaknesses (CWE)
References
- https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-30394Third Party Advisory
- https://github.com/ros-planning/moveitProduct
- https://i.ibb.co/R2JSPV5/2022-10-02-12-39-57-Window.pngBroken Link
- https://i.ibb.co/RyRSzpN/Response-Manipulation.pngBroken Link
- https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-30394Third Party Advisory
- https://github.com/ros-planning/moveitProduct
- https://i.ibb.co/R2JSPV5/2022-10-02-12-39-57-Window.pngBroken Link
- https://i.ibb.co/RyRSzpN/Response-Manipulation.pngBroken Link
FAQ
What is CVE-2023-30394?
CVE-2023-30394 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."
How severe is CVE-2023-30394?
CVE-2023-30394 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30394?
Check the references section above for vendor advisories and patch information. Affected products include: Moveit Moveit.