CVE-2019-0234

Source
https://cve.org/CVERecord?id=CVE-2019-0234
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0234.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-0234
Published
2019-07-15T22:15:12Z
Modified
2026-07-08T16:27:03Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to the latest version of Roller, which is now Roller 5.2.3.

References

Affected packages

Git / github.com/apache/roller

Affected ranges

Type
GIT
Repo
https://github.com/apache/roller
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:apache:roller:5.2.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:roller:5.2.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:roller:5.2.2:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "5.2.0"
        },
        {
            "last_affected": "5.2.0"
        },
        {
            "introduced": "5.2.1"
        },
        {
            "last_affected": "5.2.1"
        },
        {
            "introduced": "5.2.2"
        },
        {
            "last_affected": "5.2.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

5.*
5.2.0
5.2.1
5.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0234.json"