First published: Tue Oct 01 2019(Updated: )
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains UpSource | <2019.1.1412 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14961 has a CVSS score which indicates a medium severity level due to its potential for XSS attacks.
To remediate CVE-2019-14961, update JetBrains Upsource to version 2019.1.1412 or later.
CVE-2019-14961 affects JetBrains Upsource versions prior to 2019.1.1412.
CVE-2019-14961 is classified as a Cross-Site Scripting (XSS) vulnerability.
There are no recommended workarounds for CVE-2019-14961; updating the software is the best solution.