Skip to content

x/vulndb: potential Go vuln in github.com/arduino/arduino-create-agent: CVE-2023-49296 #2407

Closed
@GoVulnBot

Description

@GoVulnBot

CVE-2023-49296 references github.com/arduino/arduino-create-agent, which may be a Go module.

Description:
The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in versions prior to 1.3.6 affects the endpoint /certificate.crt and the way the web interface of the ArduinoCreateAgent handles custom error messages. An attacker that is able to persuade a victim into clicking on a malicious link can perform a Reflected Cross-Site Scripting attack on the web interface of the create agent, which would allow the attacker to execute arbitrary browser client side code. Version 1.3.6 contains a fix for the issue.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/arduino/arduino-create-agent
      vulnerable_at: 0.0.0-20231211102506-e52bb0070110
      packages:
        - package: arduino-create-agent
cves:
    - CVE-2023-49296
references:
    - advisory: https://github.com/arduino/arduino-create-agent/security/advisories/GHSA-j5hc-wx84-844h
    - fix: https://github.com/arduino/arduino-create-agent/commit/9a0e582bb8a1ff8e70d202943ddef8625ccefcc8

Metadata

Metadata

Assignees

Labels

excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions