First published: Fri Sep 25 2020(Updated: )
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Pagure | <5.6 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11556 is a vulnerability in Pagure before version 5.6 that allows cross-site scripting (XSS) attacks via the templates/blame.html blame view.
CVE-2019-11556 has a severity rating of medium, with a CVSS score of 6.1.
CVE-2019-11556 affects Pagure versions before 5.6, allowing XSS attacks via the templates/blame.html blame view.
Pagure versions before 5.6, Redhat Pagure, openSUSE Backports SLE 15.0-sp1, and openSUSE Leap 15.1 are affected by CVE-2019-11556.
To fix CVE-2019-11556, it is recommended to upgrade Pagure to version 5.6 or later.