CVE-2024-9427Medium· 5.4▾ SunlitKoji Cross-site Scripting
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code.
koji >= 1.35.0, < 1.35.1koji >= 1.34.0, < 1.34.3koji < 1.33.2Upgrade to a patched release:
koji 1.35.1koji 1.34.3koji 1.33.2