CVE-2014-3995: XSS
A cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.
Other sources
Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3995?
CVE-2014-3995 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-3995?
To fix CVE-2014-3995, upgrade Djblets to version 0.8.3 or 0.7.30.
Which versions are affected by CVE-2014-3995?
CVE-2014-3995 affects Djblets versions prior to 0.8.3 and 0.7.30.
What kind of vulnerability is CVE-2014-3995?
CVE-2014-3995 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
What software does CVE-2014-3995 impact?
CVE-2014-3995 impacts Djblets and its versions before 0.8.3 and 0.7.30.