Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole plugin
CVE-2023-38435
6.1MEDIUM
Key Information:
- Vendor
- Apache
- Vendor
- CVE Published:
- 25 July 2023
Summary
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.
Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.
Affected Version(s)
Apache Felix Healthcheck Webconsole Plugin 0 <= 2.0.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was found by xray web vulnerability scanner (github.com/chaitin/xray)