CVE-2022-23466: teler dashboard vulnerable to DOM-based cross-site scripting (XSS)
(updated )
teler prior to version <= 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the /events
endpoint, the log data displayed on the dashboard are not sanitized.
References
Code Behaviors & Features
Detect and mitigate CVE-2022-23466 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →