Medium severity6.1OSV Advisory· Published Jun 19, 2019· Updated Jun 17, 2026
CVE-2019-10085
CVE-2019-10085
Description
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.
Affected products
3Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.