CVE-2019-11454: XSS
Last updated 24 July 2024
Other sources
Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is mishandled during an viewlog operation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11454?
CVE-2019-11454 is considered a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary JavaScript on affected systems.
How do I fix CVE-2019-11454?
To fix CVE-2019-11454, upgrade Monit to version 5.25.3 or later, specifically 1:5.27.2-1, 1:5.33.0-1, or 1:5.34.0-1.
Which versions of Monit are affected by CVE-2019-11454?
Monit versions prior to 5.25.3, including all earlier versions, are affected by CVE-2019-11454.
Can I mitigate CVE-2019-11454 without upgrading?
Mitigation options are limited for CVE-2019-11454, and the best approach is to apply the necessary updates.
Does CVE-2019-11454 affect specific operating systems?
Yes, CVE-2019-11454 affects various operating systems including specific versions of Debian, Ubuntu, and Fedora.