CVE-2016-1000037: XSS
Pagure: XSS possible in file attachment endpoint
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for Pagure: XSS possible in file attachment endpoint?
The vulnerability ID for Pagure: XSS possible in file attachment endpoint is CVE-2016-1000037.
What is the severity of CVE-2016-1000037?
The severity of CVE-2016-1000037 is medium with a severity value of 6.1.
How does CVE-2016-1000037 affect Pagure?
CVE-2016-1000037 affects Pagure through its file attachment endpoint, where a cross-site scripting vulnerability is possible.
How can I fix the XSS vulnerability in Pagure's file attachment endpoint?
To fix the XSS vulnerability in Pagure's file attachment endpoint, it is recommended to update to version 5.11.3+dfsg-1 or 5.11.3+dfsg-2.1 for the debian source, or apply the necessary patches provided by the respective vendors for Redhat Pagure, Fedoraproject Fedora, and Redhat Enterprise Linux.
Where can I find more information about CVE-2016-1000037?
More information about CVE-2016-1000037 can be found in the following references: [1] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000037, [2] https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7EHB2WQ46M737B2STHQTOPTBSSQJDSS/, [3] https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000037.json