CVE-2019-14961: XSS
Published Oct 1, 2019
·Updated
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
Affected Software
1 affected component
JetBrains UpSource<2019.1.1412
Event History
Oct 1, 2019
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14961?
CVE-2019-14961 has a CVSS score which indicates a medium severity level due to its potential for XSS attacks.
2
How do I fix CVE-2019-14961?
To remediate CVE-2019-14961, update JetBrains Upsource to version 2019.1.1412 or later.
3
What software is affected by CVE-2019-14961?
CVE-2019-14961 affects JetBrains Upsource versions prior to 2019.1.1412.
4
What type of vulnerability is CVE-2019-14961?
CVE-2019-14961 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Is there a workaround for CVE-2019-14961?
There are no recommended workarounds for CVE-2019-14961; updating the software is the best solution.