Skip to content

Content Spoofing / Text Injection

High
akbarkz published GHSA-6fgx-wwc6-x2vg Feb 13, 2025

Package

No package listed

Affected versions

latest

Patched versions

None

Description

Impact

https://ubuntu.com/ is vulnerable to Content spoofing/text injection vulnerability leading to unauthorized access to any user resulting in credentials exposure of any user leading to account takeover.

Patches

No patch available yet

Workarounds

There is no need to upgrade, after merging the fix PR the issue will be gone

References

https://hackerone.com/reports/106350

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs