Vulnerability record · CVE-2020-35774 · published 29 December 2020
CVE-2020-35774: TwitterServer /histograms endpoint cross-site scripting
Twitter · Twitter Server
TwitterServer before 20.12.0 contains a reflected cross-site scripting flaw in server/handler/HistogramQueryHandler.scala that affects the /histograms endpoint in some configurations. An attacker who can get a victim to load a crafted URL can execute script in the victim's browser within the context of the affected service.
Description
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires low privileges plus user interaction, but the very high EPSS score and scope change warrant prompt patching.
What it is
TwitterServer before 20.12.0 contains a reflected cross-site scripting flaw in server/handler/HistogramQueryHandler.scala that affects the /histograms endpoint in some configurations. An attacker who can get a victim to load a crafted URL can execute script in the victim's browser within the context of the affected service.
Impact
An attacker can run arbitrary script in a victim's browser session against the TwitterServer admin interface, potentially reading data or performing actions as that user. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via the /histograms HTTP endpoint. The CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs some authenticated access plus a victim who follows a crafted link.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.85649, 99.7th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade twitter-server to 20.12.0 or later, which contains the patch commit e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c.
- If upgrade is not immediate, restrict network access to the /histograms endpoint and the admin interface to trusted networks only.
- Disable or remove the histograms handler in configurations where it is not required.
- Apply output encoding or a Content-Security-Policy to admin endpoints to reduce script execution risk.
- Audit who has access to the admin interface and reduce privileges where possible.
Detection
- Monitor web logs for requests to /histograms containing script-like or encoded payloads in query parameters.
- Alert on unexpected script content or reflected input in responses from the /histograms endpoint.
- Review access logs for the admin interface from unusual source addresses or sessions.
- Track twitter-server versions in inventory to identify hosts still below 20.12.0.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://advisory.checkmarx.net/advisory/CX-2020-4287 | Third Party Advisory |
| https://github.com/twitter/twitter-server/commit/e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c | PatchThird Party Advisory |
| https://github.com/twitter/twitter-server/compare/twitter-server-20.10.0...twitter-server-20.12.0 | PatchThird Party Advisory |
| https://advisory.checkmarx.net/advisory/CX-2020-4287 | Third Party Advisory |
| https://github.com/twitter/twitter-server/commit/e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c | PatchThird Party Advisory |
| https://github.com/twitter/twitter-server/compare/twitter-server-20.10.0...twitter-server-20.12.0 | PatchThird Party Advisory |
Track CVE-2020-35774 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.