CVE-2014-3995Cross-site Scripting in Djblets

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 38.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

PyPIreviewboard/djblets0.80.8.3+4
NVDreviewboard/djblets0.7.29+4

Patches

🔴Vulnerability Details

3
OSV
Djblets Cross-site scripting Vulnerability2022-05-17
GHSA
Djblets Cross-site scripting Vulnerability2022-05-17
OSV
CVE-2014-3995: Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars2014-06-16

💬Community

3
Bugzilla
CVE-2014-3995 python-djblets: XSS Vulnerability in Djblets gravatar templates2014-06-09
Bugzilla
CVE-2014-3995 CVE-2014-3994 python-djblets: various flaws [epel-6]2014-06-09
Bugzilla
CVE-2014-3995 python-djblets: XSS Vulnerability in Djblets gravatar templates [fedora-all]2014-06-06