CyberRota Analysis
AI-GeneratedThe vulnerability affects the Cribl Stream application, specifically its JSON Pointer-to-accessor compiler, allowing remote authenticated attackers with edit privileges to execute arbitrary JavaScript on the server through a manipulated database connection identifier or pack configuration value. This could lead to unauthorized access and potential compromise of the server's integrity. Organizations using Cribl Stream prior to version 4.18.2 should prioritize patching this vulnerability to mitigate the risk of exploitation.
Original NVD Description
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.
Related CVEs
Other vulnerabilities affecting the same vendor(s)