Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 70.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 70.00 |
VPI formula vpi-v1