|
2 | 2 | gem: oxidized-web |
3 | 3 | cve: 2019-25088 |
4 | 4 | ghsa: 8qwh-rm6c-jv96 |
5 | | -url: https://github.com/ytti/oxidized-web/pull/195 |
| 5 | +url: https://nvd.nist.gov/vuln/detail/CVE-2019-25088 |
6 | 6 | title: Oxidized Web vulnerable to Cross-site Scripting |
7 | 7 | date: 2022-12-27 |
8 | 8 | description: | |
9 | 9 | A vulnerability was found in ytti Oxidized Web. It has been classified |
10 | | - as problematic. Affected is an unknown function of the file `lib/oxidized/web/views/conf_search.haml`. |
11 | | - The manipulation of the argument `to_research` leads to cross site scripting. It |
12 | | - is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. |
13 | | - It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier |
14 | | - assigned to this vulnerability. |
| 10 | + as problematic. Affected is an unknown function of the file |
| 11 | + `lib/oxidized/web/views/conf_search.haml`. |
| 12 | +
|
| 13 | + The manipulation of the argument `to_research` leads to cross site |
| 14 | + scripting. It is possible to launch the attack remotely. |
| 15 | + The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. |
| 16 | +
|
| 17 | + It is recommended to apply a patch to fix this issue. |
| 18 | + VDB-216870 is the identifier assigned to this vulnerability. |
15 | 19 | cvss_v3: 5.4 |
| 20 | +patched_versions: |
| 21 | + - ">= 0.14.0" |
16 | 22 | related: |
17 | 23 | url: |
18 | | - - https://github.com/ytti/oxidized-web/commit/55ab9bdc68b03ebce9280b8746ef31d7fdedcc45 |
| 24 | + - https://nvd.nist.gov/vuln/detail/CVE-2019-25088 |
| 25 | + - https://rubygems.org/gems/oxidized-web/versions/0.14.0 |
| 26 | + - https://github.com/ytti/oxidized-web/releases#release-0.14.0 |
| 27 | + - https://github.com/ytti/oxidized-web/compare/0.13.1...0.14.0 |
| 28 | + - https://github.com/ytti/oxidized-web/pull/195 |
| 29 | + - https://github.com/ytti/oxidized-web/pull/195/changes/12c07e69168bb5b4dfd4dbfed857491ed095dfd0 |
19 | 30 | - https://vuldb.com/?id.216870 |
| 31 | + - https://github.com/advisories/GHSA-8qwh-rm6c-jv96 |
| 32 | +notes: | |
| 33 | + - cvss_v3 from GHSA URL. |
| 34 | + - PR#195: [escape user input to fix XSS "vulnerability"] |
| 35 | + - See /changes/ UR (fix)L in /compare/ URL. |
0 commit comments