A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| koji(PyPI) | 1.35.0 | 1.35.1 | N/A |
| koji(PyPI) | 1.34.0 | 1.34.3 | N/A |
| koji(PyPI) | 0 | 1.33.2 | N/A |
CVSS Metrics