CVE-2019-10089
Summary
| CVE | CVE-2019-10089 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-23 15:15:00 UTC |
| Updated | 2019-09-23 19:25:00 UTC |
| Description | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Jspwiki | 2.11.0 | m1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m1-rc3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m2-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m3-rc2 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc1 | All | All |
| Application | Apache | Jspwiki | 2.11.0 | m4-rc2 | All | All |
| Application | Apache | Jspwiki | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JSPWiki: CVE-2019-10089 | MISC | jspwiki-wiki.apache.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981643 Java (maven) Security Update for org.apache.jspwiki:jspwiki-war (GHSA-3rx2-x6mx-grj3)