CVE-2019-10904
Summary
| CVE | CVE-2019-10904 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-06 20:29:00 UTC |
| Updated | 2019-04-09 20:20:00 UTC |
| Description | Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 1750-1] roundup security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| oss-security - Re: XSS in roundup bug tracker 404 page |
MLIST |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| XSS on 404 page of bugs.python.org · Issue #34 · python/bugs.python.org · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| oss-security - XSS in roundup bug tracker 404 page |
MISC |
www.openwall.com |
Mailing List, Third Party Advisory |
| Issue 36391: XSS in bugs.python.org 404 error page - Python tracker |
MISC |
bugs.python.org |
Exploit, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981177 Python (pip) Security Update for roundup (GHSA-926q-wxr6-3crq)