CVE-2019-6804: XSS
Published Jan 25, 2019
·Updated
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/wfitemEdit.gsp.
Affected Software
1 affected component
PagerDuty Rundeck<3.0.13
Event History
Jan 25, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-6804?
CVE-2019-6804 is an XSS (Cross-Site Scripting) vulnerability discovered on the Job Edit page in Rundeck Community Edition before version 3.0.13.
2
What is the severity of CVE-2019-6804?
The severity of CVE-2019-6804 is medium with a CVSS score of 6.1.
3
How does CVE-2019-6804 affect Rundeck Community Edition?
CVE-2019-6804 affects Rundeck Community Edition versions before 3.0.13.
4
How can I fix CVE-2019-6804?
To fix CVE-2019-6804, you should update Rundeck Community Edition to version 3.0.13 or newer.
5
What is the CWE of CVE-2019-6804?
The CWE (Common Weakness Enumeration) of CVE-2019-6804 is CWE-79, which is a category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').