CVE-2014-3207: XSS
Published May 8, 2014
·Updated
Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to pks/lookup/undefined1.
Affected Software
12 affected components
Sks Keyserver Project Sks Keyserver<=1.1.4
Sks Keyserver Project Sks Keyserver=0.1.0
Sks Keyserver Project Sks Keyserver=0.1.1
Sks Keyserver Project Sks Keyserver=0.1.2
Sks Keyserver Project Sks Keyserver=0.1.3
Sks Keyserver Project Sks Keyserver=1.0.2
Sks Keyserver Project Sks Keyserver=1.0.3
Sks Keyserver Project Sks Keyserver=1.0.5
Sks Keyserver Project Sks Keyserver=1.1.0
Sks Keyserver Project Sks Keyserver=1.1.1
Sks Keyserver Project Sks Keyserver=1.1.2
Sks Keyserver Project Sks Keyserver=1.1.3
Remediation
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3207?
CVE-2014-3207 is categorized as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-3207?
To fix CVE-2014-3207, upgrade your SKS Keyserver to version 1.1.5 or later.
3
What versions of SKS Keyserver are affected by CVE-2014-3207?
SKS Keyserver versions before 1.1.5, including 0.1.0 through 1.1.4, are affected by CVE-2014-3207.
4
What kind of attacks can exploit CVE-2014-3207?
CVE-2014-3207 can be exploited by remote attackers to inject arbitrary web scripts or HTML into the application.
5
Is CVE-2014-3207 specific to certain environments or software configurations?
CVE-2014-3207 affects all installations of SKS Keyserver prior to version 1.1.5, regardless of the specific deployment environment.