[MAVEN:GHSA-7V7G-9VX6-VCG2] Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Impact

A reflected cross-site scripting vulnerability has been identified in Goobi viewer core when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser.

Patches

The vulnerability has been fixed in version 23.03

Credits

We would like to thank RUS-CERT for reporting this issues.

If you have any questions or comments about this advisory:
* Email us at support@intranda.com

Package Affected Version
pkg:maven/io.goobi.viewer/viewer-core < 23.03
Package Fixed Version
pkg:maven/io.goobi.viewer/viewer-core = 23.03
ID
MAVEN:GHSA-7V7G-9VX6-VCG2
Severity
moderate
URL
https://github.com/advisories/GHSA-7v7g-9vx6-vcg2
Published
2023-04-07T19:22:41
(17 months ago)
Modified
2023-04-07T19:22:43
(17 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.goobi.viewer/viewer-core io.goobi.viewer viewer-core < 23.03
Fixed pkg:maven/io.goobi.viewer/viewer-core io.goobi.viewer viewer-core = 23.03
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...