SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0234

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller.

MEDIUM 6.1EPSS 3.45%

Does this matter?

Lower severity and a low EPSS score (3.45%). Track it; it rarely justifies an emergency change on its own.

Description

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to the latest version of Roller, which is now Roller 5.2.3.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
3.45% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/roller
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.