Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user's browser. The vulnerability is patched in version 9. As a workaround, implementers who are not able to upgrade may apply DOMPurify recursively to the options structure to filter out malicious markup.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LHighcharts
APPHighcharts< 9.0.0Netapp Cloud Backup
APPNetappall versionsNetapp Oncommand Insight
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsNetapp Snapcenter
APPNetappall versions
Related vulnerabilities
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)
Apache HTTP Server 2.4.49 — path traversal i RCE (aktywnie exploitowany)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)