Medium severity5.4NVD Advisory· Published Sep 1, 2022· Updated Jun 17, 2026
CVE-2022-38790
CVE-2022-38790
Description
Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise UI via a GitopsCluster dashboard link. An annotation can be added to a GitopsCluster custom resource.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <0.9.0-rc.5
cpe:2.3:a:weave.works:gitops:*:*:*:*:enterprise:*:*:*+ 3 more
- cpe:2.3:a:weave.works:gitops:*:*:*:*:enterprise:*:*:*range: <0.9.0
- cpe:2.3:a:weave.works:gitops:0.9.0:rc1:*:*:enterprise:*:*:*
- cpe:2.3:a:weave.works:gitops:0.9.0:rc2:*:*:enterprise:*:*:*
- cpe:2.3:a:weave.works:gitops:0.9.0:rc3:*:*:enterprise:*:*:*
Patches
Vulnerability mechanics
References
4- docs.gitops.weave.works/security/cve/enterprise/CVE-2022-38790/index.htmlnvdExploitPatchVendor Advisory
- docs.gitops.weave.works/docs/cluster-management/getting-started/nvdProductVendor Advisory
- docs.gitops.weave.works/docs/intronvdProductVendor Advisory
- www.weave.works/product/gitops-enterprise/nvdProductVendor Advisory
News mentions
0No linked articles in our index yet.