CVE-2024-39125: Roundup Cross-site Scripting Vulnerability
(updated )
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
References
- github.com/advisories/GHSA-xjgw-ghrx-wfff
- github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2024-64.yaml
- github.com/roundup-tracker/roundup
- github.com/roundup-tracker/roundup/commit/860e3c8d07b05b77c6cdf5d0b6e7dbfe51b11631
- nvd.nist.gov/vuln/detail/CVE-2024-39125
- www.roundup-tracker.org/
- www.roundup-tracker.org/docs/security.html
Code Behaviors & Features
Detect and mitigate CVE-2024-39125 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →