id: PYSEC-2010-31 details: Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program. affected: - package: name: roundup ecosystem: PyPI purl: pkg:pypi/roundup ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.4.14 versions: - 0.5.9 - 0.6.11 - 0.6.8 - 0.6.9 - 0.7.0 - 0.7.0b3 - 0.7.1 - 0.7.11 - 0.7.12 - 0.7.2 - 0.7.3 - 0.7.4 - 0.7.5 - 0.7.7 - 0.7.8 - 0.7.9 - 0.8.0 - 0.8.0b1 - 0.8.1 - 0.8.2 - 0.8.3 - 0.8.4 - 0.8.5 - 0.8.6 - 0.9.0b1 - "1.0" - 1.0.1 - 1.1.0 - 1.1.1 - 1.1.2 - 1.2.0 - 1.2.1 - 1.3.0 - 1.3.1 - 1.3.2 - 1.3.3 - 1.4.0 - 1.4.1 - 1.4.10 - 1.4.11 - 1.4.12 - 1.4.13 - 1.4.2 - 1.4.3 - 1.4.4 - 1.4.5.1 - 1.4.6 - 1.4.7 - 1.4.8 - 1.4.9 references: - type: WEB url: http://lists.fedoraproject.org/pipermail/package-announce/2010-September/048221.html - type: WEB url: http://www.securityfocus.com/bid/41326 - type: WEB url: http://bugs.gentoo.org/show_bug.cgi?id=326395 - type: REPORT url: https://bugzilla.redhat.com/show_bug.cgi?id=610861 - type: WEB url: http://lists.fedoraproject.org/pipermail/package-announce/2010-September/048018.html - type: WEB url: http://roundup.svn.sourceforge.net/viewvc/roundup?view=revision&revision=4486 - type: WEB url: http://issues.roundup-tracker.org/issue2550654 - type: WEB url: http://sourceforge.net/mailarchive/message.php?msg_name=AANLkTimIYtyRzTAReGmTSCEqPYBvwkkxrP6YKrdVm_nU%40mail.gmail.com - type: ADVISORY url: http://secunia.com/advisories/41585 - type: WEB url: http://www.openwall.com/lists/oss-security/2010/07/02/12 - type: WEB url: http://lists.fedoraproject.org/pipermail/package-announce/2010-September/048061.html - type: WEB url: http://www.openwall.com/lists/oss-security/2010/07/02/3 - type: WEB url: http://roundup.svn.sourceforge.net/viewvc/roundup/roundup/trunk/roundup/cgi/client.py?r1=4486&r2=4485&pathrev=4486 - type: ADVISORY url: http://secunia.com/advisories/40433 - type: ADVISORY url: https://github.com/advisories/GHSA-frgf-rv99-862x aliases: - CVE-2010-2491 - GHSA-frgf-rv99-862x modified: "2021-08-27T03:22:19.672970Z" published: "2010-09-24T19:00:00Z"