First published: Fri Jan 17 2020(Updated: )
openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Suse Openqa | <2019-07-22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3686 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS).
To fix CVE-2019-3686, update openQA to a version later than July 22, 2019 or apply necessary security patches provided by the vendor.
CVE-2019-3686 affects openQA versions prior to commit c172e8883d8f32fced5e02f9b6faaacc913df27b released before July 22, 2019.
CVE-2019-3686 should be considered a past vulnerability; however, unpatched systems remain at risk of exploitation.
Exploiting CVE-2019-3686 could allow an attacker to execute arbitrary scripts in the context of the user’s browser.