CVE-2019-25047: XSS
Published Jun 21, 2021
·Updated
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
Affected Software
2 affected components
Greenbone Greenbone Security Assistant<8.0.2
Greenbone Greenbone OS<5.0.10
Remediation
Patch Available
Patch Available
Event History
Jun 21, 2021
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Frequently Asked Questions
1
What is CVE-2019-25047?
CVE-2019-25047 is a vulnerability that allows XSS (cross-site scripting) during 404 URL handling in Greenbone Security Assistant (GSA) before version 8.0.2 and Greenbone OS (GOS) before version 5.0.10.
2
How does CVE-2019-25047 affect Greenbone Security Assistant (GSA)?
CVE-2019-25047 allows XSS during 404 URL handling in Greenbone Security Assistant (GSA) before version 8.0.2.
3
How does CVE-2019-25047 affect Greenbone OS (GOS)?
CVE-2019-25047 allows XSS during 404 URL handling in Greenbone OS (GOS) before version 5.0.10.
4
What is the severity of CVE-2019-25047?
The severity of CVE-2019-25047 is medium with a CVSS score of 6.1.
5
How can I fix CVE-2019-25047?
To fix CVE-2019-25047, update Greenbone Security Assistant (GSA) to version 8.0.2 or later, and update Greenbone OS (GOS) to version 5.0.10 or later.