VYPR
Medium severity6.1OSV Advisory· Published Jun 19, 2019· Updated Jun 17, 2026

CVE-2019-10085

CVE-2019-10085

Description

In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.

Affected products

3
  • Apache/AlluraOSV3 versions
    allura_20110215, allura_20110218, allura_20110218.01, …+ 2 more
    • (no CPE)range: allura_20110215, allura_20110218, allura_20110218.01, …
    • cpe:2.3:a:apache:allura:*:*:*:*:*:*:*:*range: <1.11.0
    • (no CPE)range: <1.11.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.