—
PYSEC-2014-99
Quick fix
PYSEC-2014-99 — ajenti: upgrade to the fixed version with the command below.
pip install --upgrade 'ajenti>=d3fc5eb142ff16d55d158afb050af18d5ff09120'Details
Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/ajenti
Introduced in:
0Fixed in: d3fc5eb142ff16d55d158afb050af18d5ff09120Fix
pip install --upgrade 'ajenti>=d3fc5eb142ff16d55d158afb050af18d5ff09120'References
- https://github.com/Eugeny/ajenti/commit/d3fc5eb142ff16d55d158afb050af18d5ff09120[FIX]
- http://secunia.com/advisories/59177[ADVISORY]
- https://www.netsparker.com/critical-xss-vulnerabilities-in-ajenti[WEB]
- http://www.securityfocus.com/bid/68047[WEB]
- https://github.com/advisories/GHSA-2ch8-f849-pjg3[ADVISORY]