Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole plugin
CVE-2023-38435

6.1MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
25 July 2023

Summary

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.

Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

Affected Version(s)

Apache Felix Healthcheck Webconsole Plugin 0 <= 2.0.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was found by xray web vulnerability scanner (github.com/chaitin/xray)
.