Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
{ "ubuntu_priority": "medium" }