{"id":"GHSA-97wh-6hmj-g8j9","summary":"Spina Cross-site Scripting vulnerability","details":"Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1.","aliases":["CVE-2023-3445"],"modified":"2024-02-16T08:13:58.519534Z","published":"2023-06-28T15:30:23Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-06-30T20:34:45Z","nvd_published_at":"2023-06-28T14:15:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3445"},{"type":"WEB","url":"https://github.com/spinacms/spina/commit/9adfe7b4807b3cc10dbb7351a26cc32f5d8c14a3"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spina/CVE-2023-3445.yml"},{"type":"PACKAGE","url":"https://github.com/spinacms/spina"},{"type":"WEB","url":"https://huntr.dev/bounties/18a74a9d-4a2d-4bf8-ae62-56a909427070"}],"affected":[{"package":{"name":"spina","ecosystem":"RubyGems","purl":"pkg:gem/spina"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.1"}]}],"versions":["0.10.0","0.11.0","0.11.1","0.12.0","0.6.11","0.6.12","0.6.13","0.6.14","0.6.15","0.6.16","0.6.17","0.6.18","0.6.19","0.6.20","0.6.21","0.6.22","0.6.23","0.6.24","0.6.25","0.6.26","0.6.27","0.6.28","0.6.29","0.7.0","0.7.2","0.7.3","0.8.0","0.8.1","0.8.2","0.8.3","0.9.0","1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.2.0","2.0.0","2.0.0.alpha","2.0.0.beta","2.0.1","2.0.2","2.1.0","2.1.1","2.10.0","2.11.0","2.12.0","2.13.0","2.13.1","2.14.0","2.15.0","2.2.0","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.4.0","2.5.0","2.6.0","2.6.1","2.6.2","2.7.0","2.8.0","2.8.1","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-97wh-6hmj-g8j9/GHSA-97wh-6hmj-g8j9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"}]}