[MAVEN:GHSA-2C6Q-RGVJ-66RX] Apache Tiles Vulnerable to XSS via EL Expression Injection

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.

Package Affected Version
pkg:maven/org.apache.tiles/tiles-core >= 2.1, < 2.1.2
Package Fixed Version
pkg:maven/org.apache.tiles/tiles-core = 2.1.2
ID
MAVEN:GHSA-2C6Q-RGVJ-66RX
Severity
moderate
URL
https://github.com/advisories/GHSA-2c6q-rgvj-66rx
Published
2022-05-02T03:23:16
(2 years ago)
Modified
2024-01-23T18:19:44
(7 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.tiles/tiles-core org.apache.tiles tiles-core >= 2.1 < 2.1.2
Fixed pkg:maven/org.apache.tiles/tiles-core org.apache.tiles tiles-core = 2.1.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...