CVE-2013-5943: XSS
Published Sep 27, 2013
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
9 affected components
Graphite Project Graphite<=0.9.10
Graphite Project Graphite=0.9.2
Graphite Project Graphite=0.9.3
Graphite Project Graphite=0.9.4
Graphite Project Graphite=0.9.5
Graphite Project Graphite=0.9.6
Graphite Project Graphite=0.9.7
Graphite Project Graphite=0.9.8
Graphite Project Graphite=0.9.9
Remediation
Event History
Sep 27, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5943?
CVE-2013-5943 has a moderate severity as it allows for cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2013-5943?
To fix CVE-2013-5943, upgrade to Graphite version 0.9.11 or later.
3
What types of attacks are possible with CVE-2013-5943?
CVE-2013-5943 allows remote attackers to inject arbitrary web scripts or HTML into the application.
4
Which versions of Graphite are affected by CVE-2013-5943?
CVE-2013-5943 affects Graphite versions before 0.9.11, specifically 0.9.2 to 0.9.10.
5
Is CVE-2013-5943 still a concern in updated Graphite releases?
No, CVE-2013-5943 is not a concern in Graphite versions 0.9.11 and later, where this vulnerability has been patched.