CVE-2022-0571
Linux Fedora vulnerability analysis and mitigation

Overview

A reflected Cross-site Scripting (XSS) vulnerability was discovered in the Phoronix Test Suite repository prior to version 10.8.2. The vulnerability was identified in February 2022 and assigned CVE-2022-0571. The Phoronix Test Suite is an automated, open-source testing framework designed for Linux operating systems (Fedora Update).

Technical details

The vulnerability was classified as a reflected XSS issue (CWE-79) affecting the input validation mechanisms in the Phoronix Test Suite. The issue was specifically related to the handling of HTML encoded characters and other potentially malicious strings in the Phoromatic functions (GitHub Commit).

Impact

The vulnerability could allow attackers to execute malicious scripts through the web interface, potentially leading to unauthorized access to user data or session hijacking (CVE Details).

Mitigation and workarounds

The vulnerability was patched in version 10.8.2 of the Phoronix Test Suite. The fix included additional input validation to reject HTML encoded characters and potentially dangerous strings such as 'document.write', '../', 'onerror', 'onload', and 'alert(' (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Fedora vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66287HIGH8.8
  • Alma LinuxAlma Linux
  • webkitgtk-doc
NoYesDec 04, 2025
CVE-2025-12744HIGH8.8
  • Linux FedoraLinux Fedora
  • python3-abrt-container-addon
NoYesDec 03, 2025
CVE-2025-13601HIGH7.7
  • CBL MarinerCBL Mariner
  • glib2-devel
NoYesNov 26, 2025
CVE-2025-13947HIGH7.4
  • Alma LinuxAlma Linux
  • webkitgtk6.0
NoYesDec 03, 2025
CVE-2025-63938MEDIUM6.5
  • Linux DebianLinux Debian
  • tinyproxy
NoYesNov 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management