PT-2019-11634 · Invenio · Invenio-Previewer

Lnielsen

·

Published

2019-07-16

·

Updated

2019-07-31

·

CVE-2019-1020019

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: invenio-previewer versions prior to 1.0.0a12
Description: A Cross-Site Scripting (XSS) issue has been found in the JSON, Markdown, and iPython Notebook previewers. This would allow a malicious user to upload a file with embedded scripts that would be executed by a victim's browser.
Recommendations: For versions prior to 1.0.0a12, update to version 1.0.0a12 to fix the issue. As a temporary workaround, consider disabling the affected previewers by modifying the configuration to exclude 'json prismjs', 'mistune', and 'ipynb' from PREVIEWER PREFERENCE.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1020019
GHSA-J9M2-6HQ2-4R3C
PYSEC-2019-26

Affected Products

Invenio-Previewer