|
Message-ID: <CA+W_RZia02oGCMn7wGk_WFSrwv72BfRiiC2UEZnytL=P0mVNQw@mail.gmail.com> Date: Wed, 1 May 2019 14:02:58 -0400 From: Lou DeGenaro <lou.degenaro@...il.com> To: oss-security@...ts.openwall.com Cc: uima-dev@...che.org Subject: [ANNOUNCE] CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS) vulnerability fix CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS) vulnerability due to unintended execution of user supplied javascript code. Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Apache UIMA DUCC releases including and prior to 2.2.2 Description. The details of this vulnerability were reported to the Apache UIMA Private mailing list. This vulnerability relates to the user's browser processing of DUCC web page input data. The javascript comprising Apache UIMA DUCC which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code. Mitigation: Users are advised to upgrade these UIMA components to the following levels: - Apache UIMA DUCC: upgrade to 3.0.0 or later Credit: Marshall Schor Lou DeGenaro, on behalf of the Apache UIMA Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.