function htmlfile is not checking the non-alphanumeric symbols which could result in reflected XSS
External References: https://github.com/theyiyibest/Reflected-XSS-on-SockJS
Created python-sockjs-tornado tracking bugs for this issue: Affects: fedora-all [bug 1813979]
Upstream commit: https://github.com/sockjs/sockjs-node/commit/8f64d46c02d96b46357827216143c43b236edd36
ServiceMesh packages sockjs in the following components: - servicemesh-grafana - jaeger - kiali However, all components use at least 0.3.18+ and are not vulnerable to the XSS flaw.
Jaeger v1.17.0 is also not vulnerable, packaging v0.3.19 of sockjs.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-8823