CVE-2024-39610

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39610
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39610.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39610
Aliases
Published
2024-11-15T06:15:04Z
Modified
2024-11-21T00:53:29.747060Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

References

Affected packages

Git / github.com/unclebob/fitnesse

Affected ranges

Type
GIT
Repo
https://github.com/unclebob/fitnesse
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

20090112
20090214
20090321
20090513
20090818
20091121
20100103
20100303
20101101
20110104
20111025
20130530
20131110
20140201
20140418
20140623
20140630
20140901
20150106
20150114
20150119
20150202
20150217
20150218
20150223
20150226
20150424
20150814
20151230
20160515
20160618
20161105
20161106
20171015
20171210
20171212
20180127
20181221
20181222
20181223
20181224
20190110
20190118
20190119
20190127
20190202
20190216
20190224
20190406
20190409
20190416
20190417
20190418
20190421
20190428
20190508
20190620
20190628
20190716
20191110
20191217
20191229
20200108
20200128
20200205
20200304
20200307
20200308
20200404
20200501
20201213
20210410
20210516
20210605
20210606
20211006
20211030
20220319
20220815
20221102
20221219
20230503
20231029
20231203
20240219
20240707
20241023
list
v20121009
v20130911
v20131001
v20131003
v20131015
v20131016
v20131119
v20140130
v20140203
v20140705
v20140717

20160527.*

20160527.ENOVEA1

20160601.*

20160601.ENOVEA1