First published: Sat Jan 11 2020(Updated: )
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ganglia | <=3.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20379 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
To fix CVE-2019-20379, upgrade ganglia-web to version 3.7.6 or later that addresses the XSS vulnerability.
CVE-2019-20379 allows an attacker to execute arbitrary JavaScript in the context of the user's browser, leading to potential data theft or session hijacking.
Ganglia-web versions up to and including 3.7.5 are affected by CVE-2019-20379, making them vulnerable to XSS attacks.
CVE-2019-20379 is a known vulnerability within applications that use the ganglia-web frontend, and similar XSS vulnerabilities are relatively common in web applications.