CVE-2020-13959

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-13959
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13959.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13959
Aliases
Related
Published
2021-03-10T08:15:14Z
Modified
2024-09-18T01:00:21Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary JavaScript in the context of the attacked website and the attacked user. This can be abused to steal session cookies, perform requests in the name of the victim or for phishing attacks.

References

Affected packages

Debian:11 / velocity-tools

Package

Name
velocity-tools
Purl
pkg:deb/debian/velocity-tools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / velocity-tools

Package

Name
velocity-tools
Purl
pkg:deb/debian/velocity-tools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / velocity-tools

Package

Name
velocity-tools
Purl
pkg:deb/debian/velocity-tools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}