Description
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0479 | This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code. |
Github GHSA |
GHSA-vm59-329q-p468 | Cross-site Scripting in Apache UIMA |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T06:46:12.231Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-8035
No data.
Status : Modified
Published: 2019-05-01T21:29:00.550
Modified: 2026-06-17T02:04:08.647
Link: CVE-2018-8035
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA