www-announce mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jerry Cwiklik <cwik...@apache.org>
Subject [ANNOUNCE] CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS) vulnerability fix
Date Mon, 29 Apr 2019 20:33:55 GMT
CVE-2018-8035: Apache UIMA DUCC webserver cross-site scripting (XSS) 
vulnerability due to unintended execution of user supplied javascript code.

Severity: Important

Vendor:
The Apache Software Foundation

Versions Affected:
   - Apache UIMA DUCC releases including and prior to 2.2.2

Description.
The details of this vulnerability were reported to the Apache UIMA 
Private mailing list.

This  vulnerability relates to the user's browser processing of DUCC web 
page input data.

The javascript comprising Apache UIMA DUCC which runs in the user's 
browser does not sufficiently filter user supplied inputs, which may 
result in unintended execution of user supplied javascript code.

Mitigation:
Users are advised to upgrade these UIMA components to the following levels:
   - Apache UIMA DUCC: upgrade to 3.0.0 or later

Credit: Marshall Schor

Jerry Cwiklik, on behalf of the Apache UIMA Team


Mime
View raw message