cbcvebase.
CVE-2019-16935
published 2019-09-28

CVE-2019-16935: The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in…

PriorityP431medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
4.70%
90.9th percentile
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianjython< jython 2.7.2+repack1-5 (bookworm)jython 2.7.2+repack1-5 (bookworm)
debianpypy< jython 2.7.2+repack1-5 (bookworm)jython 2.7.2+repack1-5 (bookworm)
debianpython2.7< jython 2.7.2+repack1-5 (bookworm)jython 2.7.2+repack1-5 (bookworm)
jython_projectjython>= 0 < 2.7.2+repack1-52.7.2+repack1-5
jython_projectjython>= 0 < 2.7.2+repack1-52.7.2+repack1-5
jython_projectjython>= 0 < 2.7.2+repack1-52.7.2+repack1-5
pythonpython>= 2.7.0 < 2.7.172.7.17
pythonpython>= 3.0.0 < 3.5.83.5.8
pythonpython>= 3.6.0 < 3.6.103.6.10
pythonpython>= 3.7.0 < 3.7.53.7.5

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.