CVE-2024-55888

HIGH

Hush Line <0.3.5 - CSRF

Title source: llm
STIX 2.1

Description

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security headers. This could result in bypassing of cross-site scripting filters. Version 0.3.5 fixed the issue.

Scores

CVSS v3 7.1
EPSS 0.0007
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (1)
scidsg/hushline >= 0.1.0, < 0.3.5
Published Dec 12, 2024
Tracked Since Feb 18, 2026