In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/StackStorm/st2/releases/tag/v2.9.3 | third party advisory release notes |
https://github.com/StackStorm/st2/releases/tag/v2.10.3 | third party advisory release notes |
https://stackstorm.com/2019/03/08/stackstorm-2-9-3-2-10-3/ | vendor advisory |