CVE-2023-32192

A vulnerability has been identified in which unauthenticated cross-site 
scripting (XSS) in the API Server's public API endpoint can be 
exploited, allowing an attacker to execute arbitrary JavaScript code in the victim browser
Basic XSS
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
suseCNA
8.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
CISA-ADPADP
---
---