CVE-2020-13697
Summary
| CVE | CVE-2020-13697 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 08:15:00 UTC |
| Updated | 2021-02-26 20:54:00 UTC |
| Description | An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that extends this class without implementing its own GET handler is vulnerable to reflected XSS, because the GeneralHandler GET handler prints user input passed through the query string without any sanitization. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vdoo | CVE Security Advisories | MISC | www.vdoo.com | Third Party Advisory |
| GitHub - NanoHttpd/nanohttpd: Tiny, easily embeddable HTTP server in Java. | MISC | github.com | Product, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 985497 Java (maven) Security Update for org.nanohttpd:nanohttpd (GHSA-pr5m-4w22-8483)