CVE-2018-8035: Apache Uimaducc
Medium severity, CVSS 6.1. EPSS: 4.9% chance of exploitation in the next 30 days.
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.
Affected products
- Apache Uimaducc: up to and including 2.2.2
Published 2019-05-01. Last modified 2026-06-17.