PT-2020-9131 · Stroom · Stroom-App

Jonathan Leitschuh

·

Published

2020-01-28

·

Updated

2020-01-29

·

CVE-2019-10779

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions stroom:stroom-app versions prior to 5.5.12 stroom:stroom-app versions 6.0.0 through 6.0.24
Description The issue allows an attacker website to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom UI via a Cross-site Scripting vulnerability to take full control of the Stroom UI on behalf of the logged-in user.
Recommendations For versions prior to 5.5.12, update to version 5.5.12 or later. For versions 6.0.0 through 6.0.24, update to version 6.0.25 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10779
SNYK-JAVA-STROOM-541182

Affected Products

Stroom-App