CVE-2019-20379: XSS
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20379?
CVE-2019-20379 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
How do I fix CVE-2019-20379?
To fix CVE-2019-20379, upgrade ganglia-web to version 3.7.6 or later that addresses the XSS vulnerability.
What impact does CVE-2019-20379 have on my application?
CVE-2019-20379 allows an attacker to execute arbitrary JavaScript in the context of the user's browser, leading to potential data theft or session hijacking.
Which versions of ganglia-web are affected by CVE-2019-20379?
Ganglia-web versions up to and including 3.7.5 are affected by CVE-2019-20379, making them vulnerable to XSS attacks.
Is CVE-2019-20379 a common vulnerability?
CVE-2019-20379 is a known vulnerability within applications that use the ganglia-web frontend, and similar XSS vulnerabilities are relatively common in web applications.