CVE-2019-0224
Summary
| CVE | CVE-2019-0224 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-28 21:29:00 UTC |
| Updated | 2023-11-07 03:01:00 UTC |
| Description | In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Jspwiki | 2.11.0 | milestone1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1-rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone2-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone1-rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | milestone2-rc1 | All | All |
| Application | Apache | Jspwiki | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache JSPWiki CVE-2019-0224 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Patch, Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| JSPWiki: CVE-2019-0224 | CONFIRM | jspwiki-wiki.apache.org | Vendor Advisory |
| Pony Mail! | lists.apache.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982306 Java (maven) Security Update for org.apache.jspwiki:jspwiki-main (GHSA-fmpq-w5q6-9vf9)