CVE-2017-20159
low-risk
Published 2022-12-31
A vulnerability was found in rf Keynote up to 0.x on Rails. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/keynote/rumble.rb. The manipulation of the argument value leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.0.0 is able to address this issue. The patch is identified as 05be4356b0a6ca7de48da926a9b997beb5ffeb4a. It is recommended to upgrade the affected component. VDB-217142 is the identifier assigned to this vulnerability.
Do I need to act?
-
0.43% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.5/10
Low
NETWORK
/ LOW complexity
Affected Products (1)
Keynote
Affected Vendors
References (8)
Release Notes
https://github.com/rf-/keynote/releases/tag/v1.0.0
Permissions Required
https://vuldb.com/?ctiid.217142
Permissions Required
https://vuldb.com/?id.217142
Release Notes
https://github.com/rf-/keynote/releases/tag/v1.0.0
Permissions Required
https://vuldb.com/?ctiid.217142
Permissions Required
https://vuldb.com/?id.217142
23
/ 100
low-risk
Severity
16/34 · Moderate
Exploitability
2/34 · Minimal
Exposure
5/34 · Minimal