First published: Mon Jul 29 2019(Updated: )
Dependency-Track before 3.5.1 allows XSS.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Dependency-Track | <3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1020007 is a vulnerability in Dependency-Track before version 3.5.1 that allows Cross-Site Scripting (XSS) attacks.
CVE-2019-1020007 has a severity score of 5.4, which is considered medium.
CVE-2019-1020007 affects Dependency-Track versions up to, but not including, 3.5.1.
Cross-Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
To protect yourself from CVE-2019-1020007, make sure to update to version 3.5.1 or later of Dependency-Track.