Skip to content

Vulnerable Analytics-Utils Dependency in DataHub Frontend

High
david-leifker published GHSA-fmp6-j664-fqg5 Nov 14, 2023

Package

docker datahub-frontend (Docker)

Affected versions

< v0.11.0

Patched versions

v0.11.0

Description

Summary

DataHub Frontend was utilizing a vulnerable version of the analytics-utils package that was exploitable using malicious URL links to execute arbitrary Javascript on the user's browser.

Details

There was an XSS vulnerability in the version of analytics-utils that would allow an attacker to craft a malicious link to a DataHub instance. If an authenticated DataHub user clicked this link, it could result in a wide variety of attacks using executed Javascript.

PoC

An attacker would have to craft a malicious URL, coerce an authenticated user to click on it, and if the URL was crafted for example to invite a new user, could create their own user to log in as.

Impact

DataHub Frontend instances prior to v0.11 are vulnerable to such attacks.

Severity

High
8.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CVE ID

No known CVE

Weaknesses

No CWEs

Credits