7.5
CVSSv3

CVE-2018-1000164

Published: 18/04/2018 Updated: 19/06/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

It exists that gunicorn improperly handled certain input. An attacker could potentially use this issue execute a cross-site scripting (XSS) attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gunicorn gunicorn 19.4.5

debian debian linux 8.0

debian debian linux 7.0

Vendor Advisories

Gunicorn could allow cross-site scripting (XSS) attacks ...
Debian Bug report logs - #896548 gunicorn: CVE-2018-1000164 Package: gunicorn; Maintainer for gunicorn is Chris Lamb <lamby@debianorg>; Source for gunicorn is src:gunicorn (PTS, buildd, popcon) Reported by: Chris Lamb <lamby@debianorg> Date: Sun, 22 Apr 2018 08:45:04 UTC Severity: grave Tags: security Found in ve ...

Github Repositories

Unofficial library for working with Victims CVE database

victimsdb-lib This is an unofficial library for working with Victims CVE database Examples >>> from victimsdb_lib import VictimsDB >>> db = VictimsDBfrom_dir('database/') # or VictimsDBfrom_git_url('githubcom/fabric8-analytics/cvedbgit') >>> 'CVE-2018-1000164' in db True

Unofficial library for working with Victims CVE database

victimsdb-lib This is an unofficial library for working with Victims CVE database Examples >>> from victimsdb_lib import VictimsDB >>> db = VictimsDBfrom_dir('database/') # or VictimsDBfrom_git_url('githubcom/fabric8-analytics/cvedbgit') >>> 'CVE-2018-1000164' in db True