CVE-2018-8035

This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:uimaducc:*:*:*:*:*:*:*:*

History

22 May 2023, 11:36

Type Values Removed Values Added
CPE cpe:2.3:a:apache:unstructured_information_management_architecture_distributed_uima_cluster_computing:*:*:*:*:*:*:*:* cpe:2.3:a:apache:uimaducc:*:*:*:*:*:*:*:*

Information

Published : 2019-05-01 21:29

Updated : 2024-02-04 20:20


NVD link : CVE-2018-8035

Mitre link : CVE-2018-8035

CVE.ORG link : CVE-2018-8035


JSON object : View

Products Affected

apache

  • uimaducc
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')