Vulnerability Name:

CVE-2019-11556 (CCN-189378)

Assigned:2019-04-26
Published:2019-04-26
Updated:2022-11-16
Summary:Pagure before 5.6 allows XSS via the templates/blame.html blame view.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2019-11556

Source: SUSE
Type: Broken Link, Mailing List, Third Party Advisory
openSUSE-SU-2020:1765

Source: SUSE
Type: Broken Link, Mailing List, Third Party Advisory
openSUSE-SU-2020:1810

Source: CONFIRM
Type: Release Notes, Vendor Advisory
https://docs.pagure.org/pagure/changelog.html

Source: XF
Type: UNKNOWN
pagure-cve201911556-xss(189378)

Source: CCN
Type: Pagure Web site
Ensure the blame view does not render html

Source: CONFIRM
Type: Patch, Vendor Advisory
https://pagure.io/pagure/c/31a0d2950ed409550074ca52ba492f9b87ec3318?branch=ab39e95ed4dc8367e5e146e6d9a9fa6925b75618

Source: MISC
Type: Patch, Vendor Advisory
https://pagure.io/pagure/commits/master

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:pagure:*:*:*:*:*:*:*:* (Version < 5.6)

  • Configuration 2:
  • cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • OR cpe:/a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:pagure_project:pagure:2.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:pagure:pagure:3.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:pagure:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:pagure:2.3.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201911556
    V
    CVE-2019-11556
    2021-10-24
    oval:org.opensuse.security:def:64578
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:62733
    P
    avahi-autoipd-0.7-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:74644
    P
    Security update for go1.16 (Moderate)
    2021-06-18
    oval:org.opensuse.security:def:63529
    P
    bluez-cups-5.48-3.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64466
    P
    Security update for cifs-utils (Moderate)
    2021-04-13
    oval:org.opensuse.security:def:64322
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:100255
    P
    (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:62910
    P
    ocaml-4.05.0-4.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62709
    P
    libyaml-cpp0_6-0.6.1-2.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63189
    P
    vsftpd-3.0.3-5.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62710
    P
    newt-devel-0.52.20-5.35 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63391
    P
    jakarta-taglibs-standard-1.1.1-2.42 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:74518
    P
    Security update for go1.13 (Important)
    2020-12-01
    oval:org.opensuse.security:def:63755
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64424
    P
    opie-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64082
    P
    Security update for tigervnc (Critical)
    2020-12-01
    oval:org.opensuse.security:def:64216
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:93542
    P
    Security update for pagure (Moderate)
    2020-11-01
    oval:org.opensuse.security:def:110268
    P
    Security update for pagure (Moderate)
    2020-10-29
    BACK
    redhat pagure *
    opensuse leap 15.1
    opensuse backports sle 15.0 sp1
    pagure_project pagure 2.2.1
    pagure pagure 3.3.0
    redhat pagure 5.2
    redhat pagure 2.3.3