<!--X-Body-Begin-->
<!--X-User-Header-->
oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->
By Date
By Thread
</form>
<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
[ANNOUNCE] CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS) vulnerability fix
<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->
From: Lou DeGenaro <lou.degenaro () gmail com>
Date: Wed, 1 May 2019 14:02:58 -0400
<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->
<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS)
vulnerability due to unintended execution of user supplied javascript code.
Severity: Important
Vendor:
The Apache Software Foundation
Versions Affected:
- Apache UIMA DUCC releases including and prior to 2.2.2
Description.
The details of this vulnerability were reported to the Apache UIMA
Private mailing list.
This vulnerability relates to the user's browser processing of DUCC web
page input data.
The javascript comprising Apache UIMA DUCC which runs in the user's
browser does not sufficiently filter user supplied inputs, which may
result in unintended execution of user supplied javascript code.
Mitigation:
Users are advised to upgrade these UIMA components to the following levels:
- Apache UIMA DUCC: upgrade to 3.0.0 or later
Credit: Marshall Schor
Lou DeGenaro, on behalf of the Apache UIMA Team
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->
By Date
By Thread
Current thread:
[ANNOUNCE] CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS) vulnerability fix Lou DeGenaro (May 01)
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->