Vulnerabilites related to Apache - Apache UIMA DUCC
CVE-2018-8035 (GCVE-0-2018-8035)
Vulnerability from cvelistv5
Published
2019-05-01 20:16
Modified
2024-08-05 06:46
Severity ?
CWE
  • Information Disclosure
Summary
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.
Impacted products
Vendor Product Version
Apache Apache UIMA DUCC Version: Apache UIMA DUCC releases including and prior to 2.2.2
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T06:46:12.231Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://uima.apache.org/security_report"
          },
          {
            "name": "108195",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/108195"
          },
          {
            "name": "[uima-dev] 20190606 Re: upcoming board report",
            "tags": [
              "mailing-list",
              "x_refsource_MLIST",
              "x_transferred"
            ],
            "url": "https://lists.apache.org/thread.html/2f49681259b375d53431605f1c557ef8a3ed0af01a488d2e1b330053%40%3Cdev.uima.apache.org%3E"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Apache UIMA DUCC",
          "vendor": "Apache",
          "versions": [
            {
              "status": "affected",
              "version": "Apache UIMA DUCC releases including and prior to 2.2.2"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This vulnerability relates to the user\u0027s browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (\u003c= 2.2.2) which runs in the user\u0027s browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Information Disclosure",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-06-06T19:06:02",
        "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "shortName": "apache"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://uima.apache.org/security_report"
        },
        {
          "name": "108195",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/108195"
        },
        {
          "name": "[uima-dev] 20190606 Re: upcoming board report",
          "tags": [
            "mailing-list",
            "x_refsource_MLIST"
          ],
          "url": "https://lists.apache.org/thread.html/2f49681259b375d53431605f1c557ef8a3ed0af01a488d2e1b330053%40%3Cdev.uima.apache.org%3E"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "security@apache.org",
          "ID": "CVE-2018-8035",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Apache UIMA DUCC",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "Apache UIMA DUCC releases including and prior to 2.2.2"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Apache"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "This vulnerability relates to the user\u0027s browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (\u003c= 2.2.2) which runs in the user\u0027s browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Information Disclosure"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://uima.apache.org/security_report",
              "refsource": "CONFIRM",
              "url": "https://uima.apache.org/security_report"
            },
            {
              "name": "108195",
              "refsource": "BID",
              "url": "http://www.securityfocus.com/bid/108195"
            },
            {
              "name": "[uima-dev] 20190606 Re: upcoming board report",
              "refsource": "MLIST",
              "url": "https://lists.apache.org/thread.html/2f49681259b375d53431605f1c557ef8a3ed0af01a488d2e1b330053@%3Cdev.uima.apache.org%3E"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
    "assignerShortName": "apache",
    "cveId": "CVE-2018-8035",
    "datePublished": "2019-05-01T20:16:55",
    "dateReserved": "2018-03-09T00:00:00",
    "dateUpdated": "2024-08-05T06:46:12.231Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}