CVE-2023-32193 Information

Description

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman’s public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.

Reference

https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32193 https://github.com/rancher/norman/security/advisories/GHSA-r8f4-hv23-6qp6

Share on: