CVE-2019-10078
Summary
| CVE | CVE-2019-10078 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-20 21:29:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Jspwiki | 2.11.0 | m1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1.rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1.rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2-rc1 | All | All |
| Application | Apache | Jspwiki | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - [CVE-2019-10078] Apache JSPWiki Cross-site scripting vulnerability | MLIST | www.openwall.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| JSPWiki: CVE-2019-10078 | CONFIRM | jspwiki-wiki.apache.org | Vendor Advisory |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| 504 Gateway Time-out | BID | www.securityfocus.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981777 Java (maven) Security Update for org.apache.jspwiki:jspwiki-main (GHSA-hp5r-mhgp-56c9)