Description
DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a crafted URL and interacting with the page.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 4.17.1
Credits
Frank Lycops, NATO NCSC
Filip Waeytens, NATO NCSC
References
docs.cribl.io/stream/release-notes/release-v4171 (Cribl Stream 4.17.1 Security Fixes)
trust.cribl.io/notifications (Cribl Trust Portal)