MEDIUM
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors
Published Apr 6, 2019
6.1
MEDIUMCVSS 3.0
EPSS 1.58%
Description
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
Affected products
No data.
Configuration 1
- 8.0
Configuration 2
- 1.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://www.openwall.com/lists/oss-security/2019/04/07/1 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- https://bugs.python.org/issue36391 x_refsource_MISCExploitVendor Advisory
- https://github.com/advisories/GHSA-926q-wxr6-3crq Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2019-201.yaml
- https://github.com/python/bugs.python.org/issues/34 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10904
- https://pypi.org/project/roundup/2.0.0alpha0
- https://www.openwall.com/lists/oss-security/2019/04/05/1 x_refsource_MISCMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2019/04/07/1 | mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory | |
| https://bugs.python.org/issue36391 | x_refsource_MISCExploitVendor Advisory | |
| https://github.com/advisories/GHSA-926q-wxr6-3crq | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2019-201.yaml | ||
| https://github.com/python/bugs.python.org/issues/34 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/04/msg00009.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10904 | ||
| https://pypi.org/project/roundup/2.0.0alpha0 | ||
| https://www.openwall.com/lists/oss-security/2019/04/05/1 | x_refsource_MISCMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 6, 2019
Updated Aug 4, 2024
Reserved Apr 6, 2019
Link CVE-2019-10904
CISA Vulnrichment
GHSA-926Q-WXR6-3CRQ Updated n/a