Описание
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.
Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.
Ссылки
- Mailing ListNot ApplicableThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing List
- Mailing ListNot ApplicableThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия до 2.1.0 (исключая)
cpe:2.3:a:apache:felix_health_check_webconsole_plugin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01205
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 2 лет назад
Cross-site Scripting in healthcheck webconsole plugin
EPSS
Процентиль: 79%
0.01205
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79