RULE(RULE ID:338795)

Rule General Information
Release Date: 2025-04-16
Rule Name: Kubeflow Cross-Site Scripting Vulnerability (CVE-2023-6571)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://huntr.com/bounties/f02781e7-2a53-4c66-aa32-babb16434632
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/kubeflow/kubeflow