CNNVD-202511-1542 Information

CNNVD ID

CNNVD-202511-1542

CVE-2025-64744

  • CNNVD Published: 2025-11-13

Description (Chinese)

OpenObserve是OpenObserve开源的一个云原生可观察性平台。 OpenObserve 0.16.1及之前版本存在跨站脚本漏洞,该漏洞源于用户控制的输入插入到电子邮件模板时未正确转义HTML,可能导致跨站脚本攻击。

Description (English)

OpenObserve is a cloud-observable platform open to OpenObserve. OpenObserve 0.16.1 and previous versions have a cross-site script loophole, which results from a user-controlled input that is not correctly transposed to HTML when inserted into the e-mail template, which may result in a cross-site script attack.

Hazard Level

Critical

Vulnerability Type

跨站脚本

Affected Vendor

OpenObserve

Published

2025-11-13

Last Modified

2026-02-24

References

https://github.com/openobserve/openobserve/security/advisories/GHSA-3jpx-57gj-w458 https://access.redhat.com/security/cve/cve-2025-64744

Share on: