GHSA-q63q-hwf6-3mw6
MODERATECVE-2023-30093A cross-site scripting (XSS) vulnerability in Open Network Operating System (ONOS) from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the authorizationURL parameter of the API documentation dashboard under securityDefinitions > OAuth2 > authorizationURL.
- Affected
- >= 1.9.0, <= 2.7.0
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2023-05-05
- Source
- github