{
  "threat_severity" : "Moderate",
  "public_date" : "2020-02-28T00:00:00Z",
  "bugzilla" : {
    "description" : "dojo: cross-site scripting via dojox.xmpp.util.xmlEncode",
    "id" : "1831010",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1831010"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-79",
  "details" : [ "dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.", "A flaw was found in dojox. Cross-site scripting is possible as only the first occurrence of each character is encoded. The highest threat from this vulnerability is to data confidentiality and integrity." ],
  "statement" : "This flaw affects the XML encoding used on XMPP implementation at Dojo, although the FreeIPA versions shipped with Red Hat Enterprise Linux 6, 7 and 8 it doesn't make use of this specific API and are not affected by this issue.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "idm:DL1/ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Satellite 5",
    "fix_state" : "Out of support scope",
    "package_name" : "dojo",
    "cpe" : "cpe:/a:redhat:network_satellite:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-10785\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-10785\nhttps://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr" ],
  "name" : "CVE-2019-10785",
  "csaw" : false
}