{"id":"GHSA-3mqv-8gxg-pfm4","summary":"TwitterServer Cross-site Scripting via /histograms endpoint","details":"server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.","aliases":["CVE-2020-35774"],"modified":"2023-11-01T04:53:04.803025Z","published":"2022-02-09T22:37:28Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-04-07T22:16:49Z","nvd_published_at":"2020-12-29T18:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35774"},{"type":"WEB","url":"https://github.com/twitter/twitter-server/commit/e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c"},{"type":"WEB","url":"https://advisory.checkmarx.net/advisory/CX-2020-4287"},{"type":"PACKAGE","url":"https://github.com/twitter/twitter-server"},{"type":"WEB","url":"https://github.com/twitter/twitter-server/compare/twitter-server-20.10.0...twitter-server-20.12.0"}],"affected":[{"package":{"name":"com.twitter:twitter-server_2.12","ecosystem":"Maven","purl":"pkg:maven/com.twitter/twitter-server_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.12.0"}]}],"versions":["1.26.0","1.27.0","1.28.0","1.29.0","1.30.0","1.31.0","1.32.0","17.10.0","17.11.0","17.12.0","18.1.0","18.10.0","18.11.0","18.12.0","18.2.0","18.3.0","18.4.0","18.5.0","18.6.0","18.7.0","18.8.0","18.9.0","18.9.1","19.1.0","19.10.0","19.11.0","19.12.0","19.2.0","19.3.0","19.4.0","19.5.0","19.5.1","19.6.0","19.7.0","19.8.0","19.9.0","20.1.0","20.10.0","20.3.0","20.4.0","20.4.1","20.5.0","20.6.0","20.7.0","20.8.0","20.8.1","20.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-3mqv-8gxg-pfm4/GHSA-3mqv-8gxg-pfm4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}