CVE-2019-13122
Summary
| CVE | CVE-2019-13122 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-10 17:15:00 UTC |
| Updated | 2019-07-16 16:48:00 UTC |
| Description | A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 through v2.1.x. This allows an attacker to insert JavaScript or HTML into the patch detail page via an email sent to a mailing list consumed by Patchwork. This affects the function msgid in templatetags/patch.py. Patchwork versions v2.1.4 and v2.0.4 will contain the fix. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - CVE-2019-13122: Patchwork: XSS via Message-ID |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| [PATCH 0/2] XSS in Patchwork - CVE-2019-13122 |
MISC |
lists.ozlabs.org |
Mailing List, Vendor Advisory |
| Releases · getpatchwork/patchwork · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| [PATCH] docs: Add a release note for CVE-2019-13122 |
MISC |
lists.ozlabs.org |
Mailing List, Vendor Advisory |
| Commits · getpatchwork/patchwork · GitHub |
MISC |
github.com |
Third Party Advisory |
| The Patchwork July 2019 Archive by date |
MISC |
lists.ozlabs.org |
Vendor Advisory |
| patchwork |
MISC |
jk.ozlabs.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501221 Alpine Linux Security Update for patchwork