Description
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3mqv-8gxg-pfm4 | TwitterServer Cross-site Scripting via /histograms endpoint |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:09:15.249Z
Reserved: 2020-12-29T00:00:00.000Z
Link: CVE-2020-35774
No data.
Status : Modified
Published: 2020-12-29T18:15:13.057
Modified: 2024-11-21T05:28:03.257
Link: CVE-2020-35774
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA