First published: Wed Dec 11 2019(Updated: )
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/node-connect | 3.6.7-1 3.7.0-2 3.7.0+~3.4.35-1 | |
Redhat Openshift | =2.0 | |
Sencha Connect Node.js | <2.8.1 | |
openSUSE openSUSE | =13.1 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2013-7370.
The severity level of CVE-2013-7370 is medium.
The affected software of CVE-2013-7370 includes IBM Robotic Process Automation as a Service, Sencha Connect, Opensuse Opensuse, Debian Debian Linux.
To fix CVE-2013-7370, update to at least version 2.8.1 of node-connect.
You can find more information about CVE-2013-7370 at the following references: http://www.openwall.com/lists/oss-security/2014/04/21/2, http://www.openwall.com/lists/oss-security/2014/05/13/1, https://access.redhat.com/security/cve/cve-2013-7370