CVE-2019-11556: XSS
Published Sep 25, 2020
·Updated
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
Affected Software
3 affected components
redhat Pagure<5.6
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Remediation
Patch Available
Event History
Sep 25, 2020
CVE Published
via MITRE·05:56 AM
Data Sourced
via MITRE·05:56 AM
Description
Frequently Asked Questions
1
What is CVE-2019-11556?
CVE-2019-11556 is a vulnerability in Pagure before version 5.6 that allows cross-site scripting (XSS) attacks via the templates/blame.html blame view.
2
How severe is CVE-2019-11556?
CVE-2019-11556 has a severity rating of medium, with a CVSS score of 6.1.
3
How does CVE-2019-11556 affect Pagure?
CVE-2019-11556 affects Pagure versions before 5.6, allowing XSS attacks via the templates/blame.html blame view.
4
Which software versions are affected by CVE-2019-11556?
Pagure versions before 5.6, Redhat Pagure, openSUSE Backports SLE 15.0-sp1, and openSUSE Leap 15.1 are affected by CVE-2019-11556.
5
How can I fix CVE-2019-11556?
To fix CVE-2019-11556, it is recommended to upgrade Pagure to version 5.6 or later.