Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconesim.
History

Tue, 04 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconesim.
Title In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Weaknesses CWE-79
CWE-80
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-04T16:29:35.924Z

Updated: 2025-03-04T16:57:46.139Z

Reserved: 2025-02-19T16:30:47.780Z

Link: CVE-2025-27155

cve-icon Vulnrichment

Updated: 2025-03-04T16:57:41.030Z

cve-icon NVD

Status : Received

Published: 2025-03-04T17:15:18.833

Modified: 2025-03-04T17:15:18.833

Link: CVE-2025-27155

cve-icon Redhat

No data.