Impact
The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconsim.
Patches
Commit TBA contains the fixes.
Workarounds
N/A
For more information
If you have any questions or comments about this advisory, please email us at security at matrix.org.
Impact
The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconsim.
Patches
Commit TBA contains the fixes.
Workarounds
N/A
For more information
If you have any questions or comments about this advisory, please email us at security at matrix.org.