Lucene search

K
osvGoogleOSV:GHSA-3MQV-8GXG-PFM4
HistoryFeb 09, 2022 - 10:37 p.m.

TwitterServer Cross-site Scripting via /histograms endpoint

2022-02-0922:37:28
Google
osv.dev
9
twitterserver
cross-site scripting
histogramqueryhandler
twitter
software
security risk

EPSS

0.969

Percentile

99.7%

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

EPSS

0.969

Percentile

99.7%

Related for OSV:GHSA-3MQV-8GXG-PFM4