{"id":"CVE-2024-6585","details":"Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.","aliases":["GHSA-6529-6jv3-66q2"],"modified":"2026-08-12T03:51:34.420745788Z","published":"2024-08-30T22:17:28.565Z","database_specific":{"cna_assigner":"Mandiant","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6585.json"},"references":[{"type":"WEB","url":"https://github.com/lightdash/lightdash/releases/tag/0.1042.2"},{"type":"WEB","url":"https://patch-diff.githubusercontent.com/raw/lightdash/lightdash/pull/9359.patch"},{"type":"WEB","url":"https://patch-diff.githubusercontent.com/raw/lightdash/lightdash/pull/9510.patch"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2024-6585"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6585.json"},{"type":"ADVISORY","url":"https://github.com/google/security-research/security/advisories/GHSA-6529-6jv3-66q2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6585"},{"type":"FIX","url":"https://github.com/lightdash/lightdash/pull/9359"},{"type":"FIX","url":"https://github.com/lightdash/lightdash/pull/9510"},{"type":"PACKAGE","url":"https://github.com/lightdash/lightdash"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lightdash/lightdash","events":[{"introduced":"aafff6c0c5cca648989592558de523be2a100221"},{"fixed":"0e0dc42ab2ca428e78f450ac00dfb7250fcbd443"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0.1024.6"},{"fixed":"0.1042.2"}]}}],"versions":["0.1042.1","0.1042.0","0.1041.2","0.1041.1","0.1041.0","0.1040.2","0.1040.1","0.1040.0","0.1039.2","0.1039.1","0.1039.0","0.1038.5","0.1038.1","0.1038.4","0.1038.3","0.1038.2","0.1038.0","0.1037.0","0.1036.6","0.1036.5","0.1036.4","0.1036.3","0.1036.2","0.1036.1","0.1036.0","0.1035.2","0.1035.1","0.1035.0","0.1034.1","0.1034.0","0.1033.0","0.1032.0","0.1031.1","0.1031.0","0.1030.8","0.1030.7","0.1030.6","0.1030.5","0.1030.3","0.1030.4","0.1030.2","0.1030.1","0.1030.0","0.1029.1","0.1029.0","0.1028.2","0.1028.1","0.1028.0","0.1027.4","0.1027.3","0.1027.2","0.1027.1","0.1027.0","0.1026.4","0.1026.3","0.1026.2","0.1026.1","0.1026.0","0.1025.7","0.1025.6","0.1025.5","0.1025.4","0.1025.3","0.1025.2","0.1025.1","0.1025.0","0.1024.10","0.1024.9","0.1024.8","0.1024.7","0.1024.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6585.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}