Description
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2020-4287
https://github.com/twitter/twitter-server/commit/e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c
https://github.com/twitter/twitter-server/compare/twitter-server-20.10.0...twitter-server-20.12.0
Related Vulnerabilities
CVE-2022-41713 Vulnerability in npm package deep-object-diff
CVE-2020-2166 Vulnerability in maven package de.taimos:pipeline-aws
CVE-2022-45690 Vulnerability in maven package cn.hutool:hutool-json
CVE-2020-14062 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client