CVE-2019-10085: XSS
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.
Affected Software
Event History
Frequently Asked Questions
What is Apache Allura?
Apache Allura is a software platform for managing software projects and repositories.
What is the vulnerability CVE-2019-10085?
CVE-2019-10085 is a vulnerability in Apache Allura prior to version 1.11.0 that allows for stored cross-site scripting (XSS) attacks on the user dropdown selector when creating or editing tickets.
How severe is the CVE-2019-10085 vulnerability?
The CVE-2019-10085 vulnerability has a severity rating of 6.1, which is considered medium.
How can the CVE-2019-10085 vulnerability be exploited?
The CVE-2019-10085 vulnerability can be exploited by engaging with the user dropdown selector on the create or edit ticket page.
How can I fix the CVE-2019-10085 vulnerability?
To fix the CVE-2019-10085 vulnerability, you should update Apache Allura to version 1.11.0 or higher.