VYPR

puppet-gerrit

by OpenStack

CVEs (1)

  • CVE-2016-5737MedJan 12, 2017
    risk 0.40cvss 6.1epss 0.01

    The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a crafted review.