First published: Tue Jun 18 2019(Updated: )
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Allura | <1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Apache Allura is a software platform for managing software projects and repositories.
CVE-2019-10085 is a vulnerability in Apache Allura prior to version 1.11.0 that allows for stored cross-site scripting (XSS) attacks on the user dropdown selector when creating or editing tickets.
The CVE-2019-10085 vulnerability has a severity rating of 6.1, which is considered medium.
The CVE-2019-10085 vulnerability can be exploited by engaging with the user dropdown selector on the create or edit ticket page.
To fix the CVE-2019-10085 vulnerability, you should update Apache Allura to version 1.11.0 or higher.