CVE-2020-35774: XSS
Published Dec 29, 2020
·Updated
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.
Affected Software
1 affected component
Twitter twitter-server<20.12.0
Remediation
Event History
Dec 29, 2020
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35774?
CVE-2020-35774 is classified as a medium severity vulnerability due to its potential to allow XSS attacks.
2
How do I fix CVE-2020-35774?
To remediate CVE-2020-35774, upgrade to TwitterServer version 20.12.0 or later.
3
What type of vulnerability is CVE-2020-35774?
CVE-2020-35774 is an XSS (Cross-Site Scripting) vulnerability that affects the /histograms endpoint.
4
Which software versions are affected by CVE-2020-35774?
CVE-2020-35774 affects TwitterServer versions prior to 20.12.0.
5
In what configurations does CVE-2020-35774 occur?
CVE-2020-35774 can occur in specific configurations of the TwitterServer software.