There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.
https://github.com/Netflix/dispatch/releases/tag/v20201106
https://github.com/Netflix/dispatch/releases/tag/v20201106
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.md
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.md
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9299