CVE-2014-3994: XSS
A cross-site scripting (XSS) vulnerability in util/templatetags/djbletsjs.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name.
Other sources
Cross-site scripting (XSS) vulnerability in util/templatetags/djbletsjs.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3994?
CVE-2014-3994 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-3994?
To fix CVE-2014-3994, upgrade Djblets to version 0.8.3 or above, or to version 0.7.30.
What software is affected by CVE-2014-3994?
CVE-2014-3994 affects Djblets versions before 0.7.30 and 0.8.x before 0.8.3, as well as certain versions of Review Board.
What type of vulnerability is CVE-2014-3994?
CVE-2014-3994 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
How does CVE-2014-3994 impact users?
CVE-2014-3994 can lead to unauthorized actions on behalf of users, potentially compromising their data or account.