First published: Fri Aug 23 2019(Updated: )
Jooby before 1.6.4 has XSS via the default error handler.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jooby Jooby | <1.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15477 is a vulnerability in Jooby before version 1.6.4 that allows for cross-site scripting (XSS) attacks through the default error handler.
Versions of Jooby up to version 1.6.4 are affected by CVE-2019-15477.
CVE-2019-15477 has a severity rating of 6.1 (Medium).
To fix CVE-2019-15477, update your Jooby installation to version 1.6.4 or higher.
The CWE-ID of CVE-2019-15477 is CWE-79 (Cross-Site Scripting).