Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. Reference: https://security-tracker.debian.org/tracker/CVE-2019-10904 https://github.com/python/bugs.python.org/issues/34 Upstream commit: https://bitbucket.org/python/roundup/commits/51682dc2cd7e28421d749117c25bec58f632ee5f
Created roundup tracking bugs for this issue: Affects: epel-6 [bug 1698342]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.