CVE-2023-32193 Information
Nov 01, 2024
cve
Description
A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman’s public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.
Reference
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32193 https://github.com/rancher/norman/security/advisories/GHSA-r8f4-hv23-6qp6
Share on: