CVE-2017-1000426

unknown
Published 2022-05-13 Β· Modified 2025-02-15
CVSS v3
β€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
β€”

Description

MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2017-1000426 NameCVE-2017-1000426 DescriptionMapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table…

CVE-2017-1000426

NameCVE-2017-1000426
DescriptionMapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mapproxy (PTS)bullseye1.13.0-1fixed
bookworm1.15.1-2fixed
trixie4.0.2+dfsg-2fixed
forky/non-free6.0.1+dfsg-2fixed
sid/non-free6.1.0+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mapproxysourcestretch1.9.0-3+deb9u1
mapproxysource(unstable)1.10.4-1low

Notes

https://github.com/mapproxy/mapproxy/issues/322
https://github.com/mapproxy/mapproxy/commit/2e102843203c11b02c002daa08ca59d05d5eff5a (master)
https://github.com/mapproxy/mapproxy/commit/87faa667007b00ef11ee09b16707aa9ad2e8da28 (1.10.x)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://github.com/mapproxy/mapproxy/issues/322https://github.com/mapproxy/mapproxy/commit/2e102843203c11b02c002daa08ca59d05d5eff5a (master)https://github.com/mapproxy/mapproxy/commit/87faa667007b00ef11ee09b16707aa9ad2e8da28 (1.10.x)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.10.4-1
sid Fixed 1.10.4-1
forky Fixed 1.10.4-1
bullseye Fixed 1.10.4-1
bookworm Fixed 1.10.4-1

Package impact

EcosystemPackageVulnerableFixed
python PyPImapproxy<1.11.11.11.1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.