CVE-2024-22048

govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gov.uk:govuk_tech_docs:*:*:*:*:*:ruby:*:*

History

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://github.com/advisories/GHSA-x2xw-hw8g-6773 - Patch, Vendor Advisory () https://github.com/advisories/GHSA-x2xw-hw8g-6773 - Patch, Vendor Advisory
References () https://github.com/alphagov/tech-docs-gem/pull/323 - Patch, Vendor Advisory () https://github.com/alphagov/tech-docs-gem/pull/323 - Patch, Vendor Advisory
References () https://github.com/alphagov/tech-docs-gem/releases/tag/v3.3.1 - Patch, Release Notes () https://github.com/alphagov/tech-docs-gem/releases/tag/v3.3.1 - Patch, Release Notes
References () https://github.com/alphagov/tech-docs-gem/security/advisories/GHSA-x2xw-hw8g-6773 - Vendor Advisory () https://github.com/alphagov/tech-docs-gem/security/advisories/GHSA-x2xw-hw8g-6773 - Vendor Advisory
References () https://vulncheck.com/advisories/vc-advisory-GHSA-x2xw-hw8g-6773 - Patch, Third Party Advisory () https://vulncheck.com/advisories/vc-advisory-GHSA-x2xw-hw8g-6773 - Patch, Third Party Advisory

11 Jan 2024, 16:34

Type Values Removed Values Added
CPE cpe:2.3:a:gov.uk:govuk_tech_docs:*:*:*:*:*:ruby:*:*
Summary
  • (es) Las versiones de govuk_tech_docs desde la 2.0.2 hasta la 3.3.1 anteriores son afectados por una vulnerabilidad de cross site scripting. Se puede ejecutar JavaScript malicioso en el navegador del usuario si se muestra un resultado de búsqueda malicioso en la página de búsqueda.
First Time Gov.uk govuk Tech Docs
Gov.uk
References () https://github.com/advisories/GHSA-x2xw-hw8g-6773 - () https://github.com/advisories/GHSA-x2xw-hw8g-6773 - Patch, Vendor Advisory
References () https://github.com/alphagov/tech-docs-gem/pull/323 - () https://github.com/alphagov/tech-docs-gem/pull/323 - Patch, Vendor Advisory
References () https://github.com/alphagov/tech-docs-gem/releases/tag/v3.3.1 - () https://github.com/alphagov/tech-docs-gem/releases/tag/v3.3.1 - Patch, Release Notes
References () https://github.com/alphagov/tech-docs-gem/security/advisories/GHSA-x2xw-hw8g-6773 - () https://github.com/alphagov/tech-docs-gem/security/advisories/GHSA-x2xw-hw8g-6773 - Vendor Advisory
References () https://vulncheck.com/advisories/vc-advisory-GHSA-x2xw-hw8g-6773 - () https://vulncheck.com/advisories/vc-advisory-GHSA-x2xw-hw8g-6773 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

04 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-04 21:15

Updated : 2025-06-04 22:15


NVD link : CVE-2024-22048

Mitre link : CVE-2024-22048

CVE.ORG link : CVE-2024-22048


JSON object : View

Products Affected

gov.uk

  • govuk_tech_docs
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')