CVE-2024-42346
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools,
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches.
Users are advised to upgrade. There are no known workarounds for this vulnerability.
HIGH · CVSS 7.6
EPSS 0.10297
Schedule remediation
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0