CVE-2019-10779

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10779
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10779.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-10779
Related
  • SNYK-JAVA-STROOM-541182
Published
2020-01-28T01:15:10Z
Modified
2025-02-14T10:38:18.691181Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom UI via an XSS vulnerability to take full control of the Stroom UI on behalf of the logged-in user.

References

Affected packages

Git / github.com/gchq/stroom

Affected ranges

Type
GIT
Repo
https://github.com/gchq/stroom
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v5.*

v5.0-beta.10
v5.0-beta.11
v5.0-beta.12
v5.0-beta.13
v5.0-beta.14
v5.0-beta.15
v5.0-beta.16
v5.0-beta.17
v5.0-beta.18
v5.0-beta.19
v5.0-beta.20
v5.0-beta.21
v5.0-beta.22
v5.0-beta.23
v5.0-beta.24
v5.0-beta.25
v5.0-beta.26
v5.0-beta.27
v5.0-beta.28
v5.0-beta.29
v5.0-beta.30
v5.0-beta.31
v5.0-beta.32
v5.0-beta.33
v5.0-beta.34
v5.0-beta.35
v5.0-beta.36
v5.0-beta.37
v5.0-beta.38
v5.0-beta.39
v5.0-beta.4
v5.0-beta.40
v5.0-beta.41
v5.0-beta.42
v5.0-beta.43
v5.0-beta.44
v5.0-beta.45
v5.0-beta.46
v5.0-beta.47
v5.0-beta.48
v5.0-beta.48-patch1
v5.0-beta.49
v5.0-beta.5
v5.0-beta.50
v5.0-beta.51
v5.0-beta.52
v5.0-beta.53
v5.0-beta.54
v5.0-beta.55
v5.0-beta.56
v5.0-beta.56-ehcache3
v5.0-beta.56-guavacache
v5.0-beta.57
v5.0-beta.58
v5.0-beta.59
v5.0-beta.6
v5.0-beta.60
v5.0-beta.61
v5.0-beta.62
v5.0-beta.63
v5.0-beta.64
v5.0-beta.65
v5.0-beta.66
v5.0-beta.67
v5.0-beta.68
v5.0-beta.69
v5.0-beta.7
v5.0-beta.70
v5.0-beta.71
v5.0-beta.8
v5.0-beta.9
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.1-alpha.1
v5.1-beta.1
v5.1-beta.10
v5.1-beta.11
v5.1-beta.12
v5.1-beta.13
v5.1-beta.14
v5.1-beta.15
v5.1-beta.16
v5.1-beta.2
v5.1-beta.3
v5.1-beta.4
v5.1-beta.5
v5.1-beta.6
v5.1-beta.7
v5.1-beta.8
v5.1-beta.9
v5.1-no-permission-check-alpha.1
v5.1-permission-caching-alpha.1
v5.1.0
v5.2.0
v5.2.1
v5.2.2
v5.2.3
v5.2.4
v5.3.0
v5.3.0-beta.1
v5.3.0-beta.2
v5.3.0-beta.3
v5.3.0-beta.4
v5.3.1
v5.3.2
v5.3.3
v5.3.4
v5.4.0
v5.4.1
v5.4.2
v5.4.3
v5.4.4
v5.4.5
v5.4.6
v5.5.0
v5.5.0-beta.1
v5.5.0-beta.10
v5.5.0-beta.2
v5.5.0-beta.3
v5.5.0-beta.4
v5.5.0-beta.5
v5.5.0-beta.6
v5.5.0-beta.7
v5.5.0-beta.8
v5.5.0-beta.9
v5.5.1
v5.5.10
v5.5.11
v5.5.2
v5.5.3
v5.5.4
v5.5.5
v5.5.6
v5.5.7
v5.5.8
v5.5.9