|
Message-ID: <CAF1aazCqSfmaE00r_bkV2n3sbQzaUXFALBOkffKef79AcSuWxg@mail.gmail.com> Date: Thu, 11 Jul 2019 18:14:30 -0400 From: Dave <snoopdave@...il.com> To: oss-security@...ts.openwall.com Subject: [CVE-2019-0234] Reflected Cross-site Scripting (XSS) Vulnerabiulity in Apache Roller Severity: Important Vendor: The Apache Software Foundation Versions affected: Roller 5.2, 5.2.1, 5.2.2. The unsupported pre-Roller 5.1 versions may also be affected. Description: Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). Mitigation: The mitigation for this vulnerability is to upgrade to the lastest version of Roller, which is now Roller 5.2.3. Credit: This issue was discovered and reported by Muthukumar Marikani
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.