GHSA-3mqv-8gxg-pfm4

Suggest an improvement
Source
https://github.com/advisories/GHSA-3mqv-8gxg-pfm4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-3mqv-8gxg-pfm4/GHSA-3mqv-8gxg-pfm4.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3mqv-8gxg-pfm4
Aliases
Published
2022-02-09T22:37:28Z
Modified
2023-11-01T04:53:04.803025Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
TwitterServer Cross-site Scripting via /histograms endpoint
Details

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

Database specific
{
    "nvd_published_at": "2020-12-29T18:15:00Z",
    "github_reviewed_at": "2021-04-07T22:16:49Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Maven / com.twitter:twitter-server_2.12

Package

Name
com.twitter:twitter-server_2.12
View open source insights on deps.dev
Purl
pkg:maven/com.twitter/twitter-server_2.12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20.12.0

Affected versions

1.*

1.26.0
1.27.0
1.28.0
1.29.0
1.30.0
1.31.0
1.32.0

17.*

17.10.0
17.11.0
17.12.0

18.*

18.1.0
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
18.7.0
18.8.0
18.9.0
18.9.1
18.10.0
18.11.0
18.12.0

19.*

19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.5.1
19.6.0
19.7.0
19.8.0
19.9.0
19.10.0
19.11.0
19.12.0

20.*

20.1.0
20.3.0
20.4.0
20.4.1
20.5.0
20.6.0
20.7.0
20.8.0
20.8.1
20.9.0
20.10.0