This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-05-01 14:29
Updated : 2019-06-06 13:29
NVD link : CVE-2018-8035
Mitre link : CVE-2018-8035
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
apache
- unstructured_information_management_architecture_distributed_uima_cluster_computing