Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affecting github.com/kiali/kiali package, versions <1.57.4
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMKIALIKIALI-5916513
- published 25 Sep 2023
- disclosed 23 Sep 2023
- credit John Mazzitelli
Introduced: 23 Sep 2023
CVE-2022-3962 Open this link in a new tabHow to fix?
Upgrade github.com/kiali/kiali
to version 1.57.4 or higher.
Overview
github.com/kiali/kiali is a Kiali is a management console for Istio service mesh. Kiali can be quickly installed as an Istio add-on, or trusted as a part of your production environment.
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') due to improper error handling when the page or endpoint being accessed cannot be found. An attacker can perform arbitrary text injection by accessing a URL that retrieves an error response.