CVE-2013-7370: XSS
Published Dec 11, 2019
·Updated
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
Affected Software
7 affected componentsFixes available
redhat Openshift=2.0
Sencha Connect Node.js<2.8.1
openSUSE openSUSE=13.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/node-connect
3.7.0-23.7.0+~3.4.35-1
Remediation
Patch Available
Event History
Dec 11, 2019
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·05:56 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2013-7370.
2
What is the severity level of CVE-2013-7370?
The severity level of CVE-2013-7370 is medium.
3
What is the affected software of CVE-2013-7370?
The affected software of CVE-2013-7370 includes IBM Robotic Process Automation as a Service, Sencha Connect, Opensuse Opensuse, Debian Debian Linux.
4
How can I fix CVE-2013-7370?
To fix CVE-2013-7370, update to at least version 2.8.1 of node-connect.
5
Where can I find more information about CVE-2013-7370?
You can find more information about CVE-2013-7370 at the following references: http://www.openwall.com/lists/oss-security/2014/04/21/2, http://www.openwall.com/lists/oss-security/2014/05/13/1, https://access.redhat.com/security/cve/cve-2013-7370