In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/88c064c95da2f41d5435ca5b3e364925bed72cc73bcec9b3f25e4c07@%3Cdev.allura.apache.org%3E | Mailing List Vendor Advisory |
http://www.securityfocus.com/bid/108816 | Third Party Advisory VDB Entry |
https://lists.apache.org/thread.html/9a20914c4251a2ae3caebd8d0dd0056f3ac89209d6c216bb89efabd9@%3Cannounce.apache.org%3E | Mailing List Vendor Advisory |
Configurations
Information
Published : 2019-06-18 17:15
Updated : 2019-06-19 13:03
NVD link : CVE-2019-10085
Mitre link : CVE-2019-10085
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
apache
- allura