[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-16935Date: (C)2019-09-30   (M)2024-04-19


The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.1CVSS Score : 4.3
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 2.7Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: NONE
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: LOWAvailability: NONE
Integrity: LOW 
Availability: NONE 
  
Reference:
FEDORA-2019-0d3fcae639
FEDORA-2019-57462fa10d
FEDORA-2019-74ba24605e
FEDORA-2019-758824a3ff
FEDORA-2019-7ec5bb5d22
FEDORA-2019-a268ba7b23
FEDORA-2019-b06ec6159b
FEDORA-2019-d202cda4f8
USN-4151-1
USN-4151-2
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html
https://bugs.python.org/issue38243
https://github.com/python/cpython/blob/35c0809158be7feae4c4f877a08b93baea2d8291/Lib/xmlrpc/server.py#L897
https://github.com/python/cpython/blob/e007860b8b3609ce0bc62b1780efaa06241520bd/Lib/DocXMLRPCServer.py#L213
https://github.com/python/cpython/pull/16373
https://security.netapp.com/advisory/ntap-20191017-0004/
https://www.oracle.com/security-alerts/cpujul2020.html
openSUSE-SU-2019:2389
openSUSE-SU-2019:2393
openSUSE-SU-2019:2438
openSUSE-SU-2019:2453
openSUSE-SU-2020:0086

CPE    3
cpe:/o:debian:debian_linux:9.0
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
cpe:/a:python:python
CWE    1
CWE-79
OVAL    40
oval:org.secpod.oval:def:89003067
oval:org.secpod.oval:def:89050650
oval:org.secpod.oval:def:705232
oval:org.secpod.oval:def:504296
...

© SecPod Technologies