VYPR
Medium severity5.4NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026

CVE-2022-23466

CVE-2022-23466

Description

teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the /events endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version v2.0.0-rc.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
teler.appGo
>= 2.0.0-rc, < 2.0.0-rc.42.0.0-rc.4
teler.appGo
>= 2.0.0-dev, < 2.0.0-dev.22.0.0-dev.2
teler.appGo
>= 0.0.0-20220625162531-2289e90590a9, < 0.0.0-20221203202318-20f59eda24200.0.0-20221203202318-20f59eda2420
teler.appGo
>= 1.2.3-0.20220625162531-2289e90590a9, < 1.2.3-0.20221203202318-20f59eda24201.2.3-0.20221203202318-20f59eda2420

Affected products

6
  • cpe:2.3:a:teler_project:teler:2.0.0:dev:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:teler_project:teler:2.0.0:dev:*:*:*:*:*:*
    • cpe:2.3:a:teler_project:teler:2.0.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:teler_project:teler:2.0.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:teler_project:teler:2.0.0:rc:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 2.0.0-rc, < 2.0.0-rc.4
  • Range: >= v2.0.0-rc, < v2.0.0-rc.4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.