Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. scancodeio
  4. ›
  5. CVE-2023-40024

CVE-2023-40024: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

August 15, 2023

ScanCode.io is a server to script and automate software composition analysis pipelines. In the /license/ endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a detailed license view that does not exist. Attackers can exploit this vulnerability to inject malicious scripts into the response generated by the license_details_view function. When unsuspecting users visit the page, their browsers will execute the injected scripts, leading to unauthorized actions, session hijacking, or stealing sensitive information. This issue has been addressed in release 32.5.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References

  • github.com/advisories/GHSA-6xcx-gx7r-rccj
  • github.com/nexB/scancode.io/blob/dd7769fbc97c84545579cebf1dc4838214098a11/CHANGELOG.rst
  • github.com/nexB/scancode.io/releases/tag/v32.5.2
  • github.com/nexB/scancode.io/security/advisories/GHSA-6xcx-gx7r-rccj
  • nvd.nist.gov/vuln/detail/CVE-2023-40024

Code Behaviors & Features

Detect and mitigate CVE-2023-40024 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 32.5.1

Fixed versions

  • 32.5.2

Solution

Upgrade to version 32.5.2 or above.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

pypi/scancodeio/CVE-2023-40024.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:41 +0000.