CVE-2023-38435
CVSS V2 None
CVSS V3 None
Description
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.
Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.
Overview
- CVE ID
- CVE-2023-38435
- Assigner
- apache
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-07-25T15:40:05.363Z
- Last Modified Date
- 2023-07-25T15:40:05.363Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://lists.apache.org/thread/r3blhp3onr4rdbkgdyglqnccg0v79pfv | vendor-advisory mailing-list |
http://seclists.org/fulldisclosure/2023/Jul/43 | |
http://www.openwall.com/lists/oss-security/2023/07/25/10 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-38435 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38435 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 21:49:51 | Added to TrackCVE |