id: PYSEC-2020-60 details: A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violates the usage expectations by exposing this UI to outside users. affected: - package: name: locust ecosystem: PyPI purl: pkg:pypi/locust ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.3.2 versions: - "1.0" - 1.0.1 - 1.0.2 - 1.0.3 - "1.1" - 1.1.1 - "1.2" - 1.2.1 - 1.2.2 - 1.2.3 - 1.3.0 - 1.3.1 references: - type: WEB url: https://docs.locust.io/en/stable/changelog.html - type: ADVISORY url: https://github.com/advisories/GHSA-vqxw-9pg7-v7v9 aliases: - CVE-2020-28364 - GHSA-vqxw-9pg7-v7v9 modified: "2020-11-17T20:37:00Z" published: "2020-11-09T21:15:00Z"