CVE-2020-7734: Cabot Cross Site Scripting (XSS) vulnerability via Endpoint column
(updated )
All versions up to 0.11.16 of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
References
- github.com/advisories/GHSA-mqwh-r366-4224
- github.com/arachnys/cabot
- github.com/arachnys/cabot/commit/eb0b3544f8c8ab2dee4643df191da346a941734f
- github.com/arachnys/cabot/pull/694
- github.com/pypa/advisory-database/tree/main/vulns/cabot/PYSEC-2020-227.yaml
- itsmeanonartist.tech/blogs/blog2.html
- nvd.nist.gov/vuln/detail/CVE-2020-7734
- snyk.io/vuln/SNYK-PYTHON-CABOT-609862
- www.exploit-db.com/exploits/48791
Detect and mitigate CVE-2020-7734 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →