Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interfaces. The impact of exploitation may result in the compromise of local accounts managed by the Coverity platform as well as other standard impacts resulting from cross-site scripting.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interfaces. The impact of exploitation may result in the compromise of local accounts managed by the Coverity platform as well as other standard impacts resulting from cross-site scripting. | |
| Title | Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: BlackDuck
Published: 2025-03-31T14:00:20.216Z
Updated: 2025-03-31T15:13:06.890Z
Reserved: 2024-12-02T14:24:56.859Z
Link: CVE-2024-12021
Updated: 2025-03-31T15:11:37.366Z
Status : Deferred
Published: 2025-03-31T14:15:18.303
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-12021
No data.