CVE-2024-29183: Baidu Openrasp

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenRASP is a RASP solution that directly integrates its protection engine into the application server by instrumentation. There exists a reflected XSS in the /login page due to a reflection of the redirect parameter. This allows an attacker to execute arbitrary javascript with the permissions of a user after the user logins with their account.

Affected products

  • Baidu Baidu Openrasp
  • Baidu Openrasp: up to and including 1.3.7

Published 2024-04-19. Last modified 2026-06-17.