CVE-2015-3161: Beaker-Project Beaker

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.

Affected products

Published 2017-09-06. Last modified 2026-06-17.