{"id":"GHSA-fjhh-67wv-7gr4","summary":"Reflected Cross site scripting (XSS) in kairosdb","details":"KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '\"sampling\":{\"value\":\"\u003cscript\u003e' substring.","aliases":["CVE-2019-19040"],"modified":"2023-11-08T04:01:27.679908Z","published":"2022-11-03T18:42:42Z","database_specific":{"github_reviewed_at":"2022-11-03T18:42:42Z","nvd_published_at":"2019-11-17T21:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19040"},{"type":"WEB","url":"https://github.com/kairosdb/kairosdb/issues/569"},{"type":"WEB","url":"https://github.com/kairosdb/kairosdb/pull/593"},{"type":"WEB","url":"https://github.com/kairosdb/kairosdb/milestone/10?closed=1"}],"affected":[{"package":{"name":"org.kairosdb:kairosdb","ecosystem":"Maven","purl":"pkg:maven/org.kairosdb/kairosdb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0"}]}],"versions":["0.9.4","0.9.4-5","1.0.0-1","1.1.0-1","1.1.1-1","1.1.2-1","1.1.3-1","1.2.0-1","1.2.1-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-fjhh-67wv-7gr4/GHSA-fjhh-67wv-7gr4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}