[MAVEN:GHSA-G66Q-GRXC-64J3] Cross-site Scripting in JavaMelody

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.

Package Affected Version
pkg:maven/net.bull.javamelody/javamelody-core <= 1.60.0
Package Fixed Version
pkg:maven/net.bull.javamelody/javamelody-core = 1.61.0
ID
MAVEN:GHSA-G66Q-GRXC-64J3
Severity
moderate
URL
https://github.com/advisories/GHSA-g66q-grxc-64j3
Published
2022-05-14T03:10:57
(2 years ago)
Modified
2023-01-27T05:02:14
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/net.bull.javamelody/javamelody-core net.bull.javamelody javamelody-core <= 1.60.0
Fixed pkg:maven/net.bull.javamelody/javamelody-core net.bull.javamelody javamelody-core = 1.61.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...