CVE-2018-1319: XSS
Published Mar 15, 2018
·Updated
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.
Affected Software
1 affected component
Apache Allura<=1.8.0
Event History
Mar 15, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-1319?
CVE-2018-1319 is a vulnerability in Apache Allura prior to version 1.8.1 that allows attackers to craft URLs that cause HTTP response splitting.
2
What is the severity of CVE-2018-1319?
CVE-2018-1319 has a severity rating of 6.1, which is considered medium.
3
How does CVE-2018-1319 affect Apache Allura?
CVE-2018-1319 affects Apache Allura versions up to and including 1.8.0.
4
What are the potential consequences of CVE-2018-1319?
The potential consequences of CVE-2018-1319 include XSS (cross-site scripting) attacks and denial of service for the victim's browsing session.
5
How can I fix CVE-2018-1319?
To fix CVE-2018-1319, users should upgrade to Apache Allura version 1.8.1 or later.