The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Enterprise Linux Subscribe
Openshift Do Subscribe
Rhel Software Collections Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2280-1 python3.5 security update
Debian DLA Debian DLA DLA-2628-1 python2.7 security update
EUVD EUVD EUVD-2019-7426 The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.
Ubuntu USN Ubuntu USN USN-4151-1 Python vulnerabilities
Ubuntu USN Ubuntu USN USN-4151-2 Python vulnerabilities
Ubuntu USN Ubuntu USN USN-6891-1 Python vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html cve-icon cve-icon
https://bugs.python.org/issue38243 cve-icon cve-icon
https://github.com/python/cpython/blob/35c0809158be7feae4c4f877a08b93baea2d8291/Lib/xmlrpc/server.py#L897 cve-icon cve-icon
https://github.com/python/cpython/blob/e007860b8b3609ce0bc62b1780efaa06241520bd/Lib/DocXMLRPCServer.py#L213 cve-icon cve-icon
https://github.com/python/cpython/pull/16373 cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2019-16935 cve-icon
https://security.netapp.com/advisory/ntap-20191017-0004/ cve-icon cve-icon
https://usn.ubuntu.com/4151-1/ cve-icon cve-icon
https://usn.ubuntu.com/4151-2/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2019-16935 cve-icon
https://www.oracle.com/security-alerts/cpujul2020.html cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:24:48.547Z

Reserved: 2019-09-28T00:00:00.000Z

Link: CVE-2019-16935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-28T02:15:10.463

Modified: 2024-11-21T04:31:23.140

Link: CVE-2019-16935

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-09-21T00:00:00Z

Links: CVE-2019-16935 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses