[MAVEN:GHSA-MJV2-6JV4-VRG7] OpenNMS Meridian and Horizon vulnerable to Cross-site Scripting

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information.

Package Affected Version
pkg:maven/org.opennms/opennms < 31.0.4
Package Fixed Version
pkg:maven/org.opennms/opennms = 31.0.4
ID
MAVEN:GHSA-MJV2-6JV4-VRG7
Severity
moderate
URL
https://github.com/advisories/GHSA-mjv2-6jv4-vrg7
Published
2023-02-23T15:33:05
(19 months ago)
Modified
2023-03-03T23:11:15
(18 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.opennms/opennms org.opennms opennms < 31.0.4
Fixed pkg:maven/org.opennms/opennms org.opennms opennms = 31.0.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...