QID 981177
QID 981177: Python (pip) Security Update for roundup (GHSA-926q-wxr6-3crq)
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-926q-wxr6-3crq for updates pertaining to this vulnerability.
Vendor References
- GHSA-926q-wxr6-3crq -
github.com/advisories/GHSA-926q-wxr6-3crq
CVEs related to QID 981177
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-926q-wxr6-3crq | roundup |
|