-
Bug
-
Resolution: Done-Errata
-
Normal
-
None
-
1
-
False
-
-
False
-
CNV v4.13.8.rhel9-427
-
---
-
---
-
-
Storage Core Sprint 250, Storage Core Sprint 251, Storage Core Sprint 252
-
No
containerized-data-importer project contains high vulnerabilities [1] [2] [3] "Cross-site Scripting (XSS)" in file pkg/uploadproxy/uploadproxy.go in branch release-v1.56
[1] https://app.snyk.io/org/red-hat-openshift-virtualisation/project/a80f6fd4-cc6c-4c94-aa84-62d403a0c94d#issue-23a8caf0-5e87-4d2c-b325-ba7d649422b9
[2] https://app.snyk.io/org/red-hat-openshift-virtualisation/project/a80f6fd4-cc6c-4c94-aa84-62d403a0c94d#issue-23b1db81-6805-4dcb-ba1f-1cbd01367e40
[3] https://app.snyk.io/org/red-hat-openshift-virtualisation/project/a80f6fd4-cc6c-4c94-aa84-62d403a0c94d#issue-8ce55a7e-128c-43c0-a6c2-3788e96a4cf2
- is related to
-
CNV-36322 Tracker of SAST Issues
- New
- links to
-
RHEA-2023:122979 OpenShift Virtualization 4.16.0 Images