Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc1MzQtcTR4Zi1oNXYy
XSS in Mapfish Print relating to JSONP support
Impact
A user can use the JSONP support to do a Cross-site scripting.
Patches
Use version >= 3.24
Workarounds
No
References
- https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e
- https://cwe.mitre.org/data/definitions/79.html
For more information
If you have any questions or comments about this advisory Comment the pull request: https://github.com/mapfish/mapfish-print/pull/1397
Permalink: https://github.com/advisories/GHSA-w534-q4xf-h5v2JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc1MzQtcTR4Zi1oNXYy
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 4 years ago
Updated: over 1 year ago
CVSS Score: 9.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Identifiers: GHSA-w534-q4xf-h5v2, CVE-2020-15231
References:
- https://github.com/mapfish/mapfish-print/security/advisories/GHSA-w534-q4xf-h5v2
- https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e
- https://nvd.nist.gov/vuln/detail/CVE-2020-15231
- https://github.com/advisories/GHSA-w534-q4xf-h5v2
Blast Radius: 17.7
Affected Packages
maven:org.mapfish.print:print-standalone
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: < 3.24
Fixed in: 3.24
All affected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions:
maven:org.mapfish.print:print-servlet
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: < 3.24
Fixed in: 3.24
All affected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.10.1, 3.10.2, 3.10.3, 3.10.4, 3.10.5, 3.10.6, 3.10.7, 3.10.8, 3.11.0, 3.11.1, 3.11.2, 3.11.3, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions:
maven:org.mapfish.print:print-lib
Dependent packages: 0Dependent repositories: 80
Downloads:
Affected Version Ranges: < 3.24
Fixed in: 3.24
All affected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.10.1, 3.10.2, 3.10.3, 3.10.4, 3.10.5, 3.10.6, 3.10.7, 3.10.8, 3.11.0, 3.11.1, 3.11.2, 3.11.3, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: