[MAVEN:GHSA-MHXG-2XF7-4XWX] Apache Helix UI vulnerable to Open Redirect

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to and including 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding. User please upgrade to 1.1.0 to fix this issue.

Package Affected Version
pkg:maven/org.apache.helix/helix >= 0.8.0, < 1.1.0
Package Fixed Version
pkg:maven/org.apache.helix/helix = 1.1.0
ID
MAVEN:GHSA-MHXG-2XF7-4XWX
Severity
moderate
URL
https://github.com/advisories/GHSA-mhxg-2xf7-4xwx
Published
2022-12-19T12:30:23
(21 months ago)
Modified
2023-01-27T05:03:46
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.helix/helix org.apache.helix helix >= 0.8.0 < 1.1.0
Fixed pkg:maven/org.apache.helix/helix org.apache.helix helix = 1.1.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...