Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | migration-planner: credentialUrl Validator Accepts javascript: URLs | Migration-planner: credentialurl validator accepts javascript: urls |
| References |
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubev2v
Kubev2v migration-planner |
|
| Vendors & Products |
Kubev2v
Kubev2v migration-planner |
Thu, 11 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information. | |
| Title | migration-planner: credentialUrl Validator Accepts javascript: URLs | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-14T14:36:00.938Z
Reserved: 2026-06-09T17:03:29.627Z
Link: CVE-2026-53472
Updated: 2026-08-14T14:35:54.798Z
Status : Received
Published: 2026-08-14T14:16:51.753
Modified: 2026-08-14T15:17:09.770
Link: CVE-2026-53472
OpenCVE Enrichment
Updated: 2026-06-11T10:42:20Z