Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04cGYyLXFqNHYtZmo2NM4AA5c1
Apache Answer Cross-site Scripting vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.
XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.
Users are recommended to upgrade to version 1.2.5, which fixes the issue.
Permalink: https://github.com/advisories/GHSA-8pf2-qj4v-fj64JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cGYyLXFqNHYtZmo2NM4AA5c1
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 9 months ago
Updated: 9 months ago
Identifiers: GHSA-8pf2-qj4v-fj64, CVE-2024-23349
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-23349
- https://lists.apache.org/thread/y5902t09vfgy7892z3vzr1zq900sgyqg
- http://www.openwall.com/lists/oss-security/2024/02/22/2
- https://github.com/advisories/GHSA-8pf2-qj4v-fj64
Affected Packages
go:github.com/apache/incubator-answer
Dependent packages: 21Dependent repositories: 0
Downloads:
Affected Version Ranges: < 1.2.5
Fixed in: 1.2.5
All affected versions: 0.2.0, 0.3.0, 0.4.0, 0.4.1, 0.4.2, 0.5.0, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.0, 1.2.1
All unaffected versions: 1.2.5