Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q23-g7mf-xp98

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting in Apache DeltaSpike

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.

Пакеты

Наименование

org.apache.deltaspike.modules:jsf-module-project

maven
Затронутые версииВерсия исправления

< 1.8.1

1.8.1

EPSS

Процентиль: 83%
0.01817
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
около 8 лет назад

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.

CVSS3: 6.1
nvd
около 8 лет назад

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.

EPSS

Процентиль: 83%
0.01817
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79