{"api_version":"1","generated_at":"2026-07-23T11:02:22+00:00","cve":"CVE-2019-13122","urls":{"html":"https://cve.report/CVE-2019-13122","api":"https://cve.report/api/cve/CVE-2019-13122.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13122","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13122"},"summary":{"title":"CVE-2019-13122","description":"A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 through v2.1.x. This allows an attacker to insert JavaScript or HTML into the patch detail page via an email sent to a mailing list consumed by Patchwork. This affects the function msgid in templatetags/patch.py. Patchwork versions v2.1.4 and v2.0.4 will contain the fix.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-07-10 17:15:00","updated_at":"2019-07-16 16:48:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2019/07/05/1","name":"[oss-security] 20190705 CVE-2019-13122: Patchwork: XSS via Message-ID","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2019-13122: Patchwork: XSS via Message-ID","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005870.html","name":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005870.html","refsource":"MISC","tags":["Mailing List","Vendor Advisory"],"title":"[PATCH 0/2] XSS in Patchwork - CVE-2019-13122","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/getpatchwork/patchwork/releases","name":"https://github.com/getpatchwork/patchwork/releases","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Releases · getpatchwork/patchwork · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005878.html","name":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005878.html","refsource":"MISC","tags":["Mailing List","Vendor Advisory"],"title":"[PATCH] docs: Add a release note for CVE-2019-13122","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/getpatchwork/patchwork/commits/master","name":"https://github.com/getpatchwork/patchwork/commits/master","refsource":"MISC","tags":["Third Party Advisory"],"title":"Commits · getpatchwork/patchwork · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/date.html","name":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/date.html","refsource":"MISC","tags":["Vendor Advisory"],"title":"The Patchwork July 2019 Archive by date","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jk.ozlabs.org/projects/patchwork/","name":"http://jk.ozlabs.org/projects/patchwork/","refsource":"MISC","tags":["Vendor Advisory"],"title":"patchwork","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13122","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13122","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13122","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ozlabs","cpe5":"patchwork","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13122","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ozlabs","cpe5":"patchwork","cpe6":"2.1.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13122","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ozlabs","cpe5":"patchwork","cpe6":"2.1.0","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13122","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ozlabs","cpe5":"patchwork","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13122","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ozlabs","cpe5":"patchwork","cpe6":"2.1.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13122","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ozlabs","cpe5":"patchwork","cpe6":"2.1.0","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-13122","qid":"501221","title":"Alpine Linux Security Update for patchwork"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-13122","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 through v2.1.x. This allows an attacker to insert JavaScript or HTML into the patch detail page via an email sent to a mailing list consumed by Patchwork. This affects the function msgid in templatetags/patch.py. Patchwork versions v2.1.4 and v2.0.4 will contain the fix."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/getpatchwork/patchwork/releases","refsource":"MISC","name":"https://github.com/getpatchwork/patchwork/releases"},{"url":"https://github.com/getpatchwork/patchwork/commits/master","refsource":"MISC","name":"https://github.com/getpatchwork/patchwork/commits/master"},{"url":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/date.html","refsource":"MISC","name":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/date.html"},{"url":"http://jk.ozlabs.org/projects/patchwork/","refsource":"MISC","name":"http://jk.ozlabs.org/projects/patchwork/"},{"refsource":"MLIST","name":"[oss-security] 20190705 CVE-2019-13122: Patchwork: XSS via Message-ID","url":"http://www.openwall.com/lists/oss-security/2019/07/05/1"},{"refsource":"MISC","name":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005870.html","url":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005870.html"},{"refsource":"MISC","name":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005878.html","url":"https://lists.ozlabs.org/pipermail/patchwork/2019-July/005878.html"}]}},"nvd":{"publishedDate":"2019-07-10 17:15:00","lastModifiedDate":"2019-07-16 16:48:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ozlabs:patchwork:2.1.0:rc2:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ozlabs:patchwork:2.1.0:rc1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ozlabs:patchwork:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"2.1.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ozlabs:patchwork:*:*:*:*:*:*:*:*","versionStartIncluding":"1.1","versionEndExcluding":"2.0.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13122","Ordinal":"151480","Title":"CVE-2019-13122","CVE":"CVE-2019-13122","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13122","Ordinal":"1","NoteData":"A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 through v2.1.x. This allows an attacker to insert JavaScript or HTML into the patch detail page via an email sent to a mailing list consumed by Patchwork. This affects the function msgid in templatetags/patch.py. Patchwork versions v2.1.4 and v2.0.4 will contain the fix.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13122","Ordinal":"2","NoteData":"2019-07-10","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13122","Ordinal":"3","NoteData":"2019-07-10","Type":"Other","Title":"Modified"}]}}}