Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2477 to the following vulnerability: Name: CVE-2010-2477 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2477 Assigned: 20100628 Reference: MLIST:[oss-security] 20100629 CVE request: XSS in python paste Reference: URL: http://marc.info/?l=oss-security&m=127785414818815&w=2 Reference: MLIST:[oss-security] 20100630 Re: CVE request: XSS in python paste Reference: URL: http://marc.info/?l=oss-security&m=127792576822169&w=2 Reference: MLIST:[pylons-discuss] 20100624 Paste 1.7.4, security fix for XSS hole Reference: URL: http://groups.google.com/group/pylons-discuss/msg/8c256dc076a408d8?dmode=source&output=gplain Reference: CONFIRM: http://bitbucket.org/ianb/paste/changeset/fcae59df8b56 Reference: CONFIRM: http://pylonshq.com/articles/archives/2010/6/paste_174_released_addresses_xss_security_hole Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.
Statement: This issue did not affect python-paste version as shipped with Red Hat Enterprise Linux 6, which included the fixed version since its initial release.