Bug 2355332 (CVE-2025-26619)
| Summary: | CVE-2025-26619 vega: Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode `expressionInterpeter` | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | caswilli, kaycoth |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A Cross-site scripting vulnerability was found in the Vega library for Node.js. In affected versions, it is possible to call JavaScript functions from the Vega expression language that were not meant to be supported.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2355646, 2355647 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-03-27 14:01:37 UTC
|