CVE-2019-10087
Summary
| CVE | CVE-2019-10087 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-23 15:15:00 UTC |
| Updated | 2019-09-23 19:08:00 UTC |
| Description | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Jspwiki | 2.11.0 | m1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc2 | All | All |
| Application | Apache | Jspwiki | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JSPWiki: CVE-2019-10087 | MISC | jspwiki-wiki.apache.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981644 Java (maven) Security Update for org.apache.jspwiki:jspwiki-war (GHSA-gwfq-qwmp-x9xg)