CVE-2024-53257

V

itess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template instead of rendering with a proper HTML templating engine. This vulnerability is fixed in 21.0.1, 20.0.4, and 19.0.8.

Configurations

No configuration.

History

03 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 16:15

Updated : 2024-12-03 16:15


NVD link : CVE-2024-53257

Mitre link : CVE-2024-53257

CVE.ORG link : CVE-2024-53257


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')