« Volver al listado

CVE-2026-42538

Estado: AplazadaMedia (6.3)—

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also creates another instance of a Cross-Site Scripting (XSS) vulnerability. Version 2.4.28 contains a patch.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42538",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42538",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-05T20:07:05.741297Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "dfir-iris",
          "product": "iris-web",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.4.28"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-04T21:16:30.730",
  "references": [
    {
      "url": "https://github.com/dfir-iris/iris-web/security/advisories/GHSA-m624-7744-2mhf",
      "source": "security-advisories@github.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/05/19/8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/dfir-iris/iris-web/security/advisories/GHSA-m624-7744-2mhf",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also creates another instance of a Cross-Site Scripting (XSS) vulnerability. Version 2.4.28 contains a patch."
    },
    {
      "lang": "es",
      "value": "IRIS es una plataforma web colaborativa que ayuda a los respondedores de incidentes a compartir detalles técnicos durante las investigaciones. Las versiones anteriores a la 2.4.28 no validan correctamente los archivos subidos. Por lo tanto, la aplicación puede ser mal utilizada para alojar páginas de phishing, entre otras cosas. Esto también crea otra instancia de una vulnerabilidad de cross-site scripting (XSS). La versión 2.4.28 contiene un parche."
    }
  ],
  "lastModified": "2026-07-22T20:10:00.127",
  "sourceIdentifier": "security-advisories@github.com"
}