Rewterz
Rewterz Threat Advisory – Multiple F5 BIG-IP Security Vulnerabilities
March 11, 2021
Rewterz
Rewterz Threat Alert – APT34 (OilRig) – IoCs
March 11, 2021

Rewterz Threat Advisory – CVE-2020-13959 – Apache Velocity Tools cross-site scripting

Severity

High

Analysis Summary

CVE-2020-13959

Apache Velocity Tools is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the default error page for VelocityView. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact

Cross site scripting

Affected Vendors

Apache

Affected Products

Apache Velocity Tools 3.0

Remediation

Upgrade to the latest version of Velocity Tools (3.1 or later).

Apache Web site