CVE-2019-9580: XSS
Published Mar 9, 2019
·Updated
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
Affected Software
2 affected components
StackStorm StackStorm<2.9.3
StackStorm StackStorm>=2.10.0<2.10.3
Event History
Mar 9, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-9580.
2
What is the severity of CVE-2019-9580?
The severity of CVE-2019-9580 is medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2019-9580?
CVE-2019-9580 affects StackStorm Web UI versions before 2.9.3 and 2.10.x before 2.10.3.
4
How can the CORS protection mechanism be bypassed in CVE-2019-9580?
In CVE-2019-9580, the CORS protection mechanism can be bypassed by using a "null" origin value.
5
What is the potential impact of CVE-2019-9580?
CVE-2019-9580 has the potential to lead to XSS (Cross-Site Scripting) attacks.