VulnerabilityModified
CVE-2019-20798
An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104.
HIGH 8.4EPSS 1.65%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.
- CVSS 3.1
- 8.4 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cherokee-project/cherokee
- Source
- cve@mitre.org
References
- https://github.com/cherokee/webserver/issues/1227Exploit, Third Party Advisory
- https://logicaltrust.net/blog/2019/11/cherokee.htmlExploit, Third Party Advisory
- https://security.gentoo.org/glsa/202012-09Third Party Advisory
- https://github.com/cherokee/webserver/issues/1227Exploit, Third Party Advisory
- https://logicaltrust.net/blog/2019/11/cherokee.htmlExploit, Third Party Advisory
- https://security.gentoo.org/glsa/202012-09Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.