CVE-2019-0224: XSS
Published Mar 28, 2019
·Updated
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.
Affected Software
7 affected components
Apache JSPWiki>=2.9.0<=2.10.5
Apache JSPWiki=2.11.0-milestone1
Apache JSPWiki=2.11.0-milestone1-rc1
Apache JSPWiki=2.11.0-milestone1-rc2
Apache JSPWiki=2.11.0-milestone1-rc3
Apache JSPWiki=2.11.0-milestone2
Apache JSPWiki=2.11.0-milestone2-rc1
Remediation
Event History
Mar 28, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the impact of CVE-2019-0224?
A carefully crafted URL could execute JavaScript on another user's session.
2
Can an attacker save information on the server or jspwiki database with CVE-2019-0224?
No, an attacker cannot save any information on the server or the JSPWiki database.
3
Is it possible to execute JavaScript on someone else's browser with CVE-2019-0224?
No, the vulnerability only allows executing JavaScript on the attacker's browser.
4
Which versions of Apache JSPWiki are affected by CVE-2019-0224?
Versions 2.9.0 to 2.11.0.M2 are affected.
5
How severe is the CVE-2019-0224 vulnerability?
The vulnerability has a severity rating of 6.1 (medium).