ADVISORIES
GEM
SEVERITY
CVSS v3.x: 8.1 (High)
UNAFFECTED VERSIONS
- < 0.14.0
PATCHED VERSIONS
- ~> 0.26.6
- >= 0.27.3
DESCRIPTION
Impact
The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing.
Patches
The problem was patched in v0.27.3 and v0.26.6