CVE-2020-13697
NanoHTTPD Cross-site Scripting vulnerability
EPSS 0.22%
描述
An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that extends this class without implementing its own GET handler is vulnerable to reflected XSS, because the GeneralHandler GET handler prints user input passed through the query string without any sanitization.
如何修補 CVE-2020-13697
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
CVE-2020-13697 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, <= 2.3.1
參考連結(5)
- ADVISORYnvd.nist.gov/vuln/detail/CVE-2020-13697
- PATCHgithub.com/NanoHttpd/nanohttpd
- WEBgithub.com/NanoHttpd/nanohttpd/blob/efb2ebf85a2b06f7c508aba9eaad5377e3a01e81/nanolets/pom.xml
- WEBgithub.com/NanoHttpd/nanohttpd/blob/efb2ebf85a2b06f7c508aba9eaad5377e3a01e81/nanolets/src/main/java/org/nanohttpd/router/RouterNanoHTTPD.java