CVE-2022-30278
About
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation to supply content. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.
Rainforest analyst review
The cross-site scripting here doesn't live in Black Duck Hub's own application logic but in the MadCap Flare documentation framework embedded in its help system: improper validation of user-supplied input to that embedded help lets an unauthenticated remote attacker land script by getting a user to click a crafted link. When the victim follows it, the payload executes in their browser session and can reach sensitive browser-based information tied to the Hub interface.
Reflected XSS is interaction-gated by nature — the attacker has to craft a malicious link and convince a target to click it, so this is a phishing-shaped vector, not a self-firing or mass-exploited one. The value is scoped to what an attacker can do inside the victim's authenticated browser context: session-riding, reading interface data, or pivoting UI actions. That it's parked in bundled help documentation rather than a core function also means it's a peripheral surface, which together with the click requirement keeps it firmly at medium.
Our angle is proportionate ranking plus web-layer detection. We'd note that the flaw is in an embedded third-party doc framework, treat it as a patch-on-cadence item on Black Duck Hub's line, and rank it below anything unauthenticated-and-automatic. Where we have web filtering or proxy logging in front of the Hub, we'd watch for the reflected-XSS request pattern hitting the help documentation paths, and reinforce the usual message that suspicious links into internal tools shouldn't be clicked — since user interaction is the only way this fires.
References
Related CVEs
Frequently asked questions
What is CVE-2022-30278?
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation to supply content.
How severe is CVE-2022-30278?
CVE-2022-30278 carries a CVSS 3.1 base score of 6.1, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 67 out of 100, in the elevated band.
How is CVE-2022-30278 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction Required. Impact on confidentiality Low, integrity Low and availability None.
Which products are affected by CVE-2022-30278?
Public advisories list the following as affected: black duck hub. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-30278?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
