The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser. The vulnerability has been fixed in version 23.03.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29014.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
]
}{
"cpe": "cpe:2.3:a:intranda:goobi_viewer_core:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "23.03"
}
]
}[
{
"digest": {
"length": 173.0,
"function_hash": "320678812675398316886619201456861700651"
},
"signature_version": "v1",
"source": "https://github.com/intranda/goobi-viewer-core/commit/c29efe60e745a94d03debc17681c4950f3917455",
"signature_type": "Function",
"target": {
"function": "setLogid",
"file": "goobi-viewer-core/src/main/java/io/goobi/viewer/managedbeans/ActiveDocumentBean.java"
},
"id": "CVE-2023-29014-263fd9f3",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"194237274387820483285555720338438146856",
"278987439396416412172397553628023902396",
"201954714797134749884745586664843042732",
"87290757374547165797192455798430417469",
"100343177534606327714330328216077114818",
"181052812292893404789684267392400076361",
"144362003394541795203797343770918399149",
"270823205961218484720632948106025191647",
"48853697312153384527786250577070154152",
"57866697294630643627304968147629937603",
"28818073947952937049981789012657029629",
"123818509013632361957017094886089935287",
"290824651556192161751544560397419313793"
]
},
"signature_version": "v1",
"source": "https://github.com/intranda/goobi-viewer-core/commit/c29efe60e745a94d03debc17681c4950f3917455",
"signature_type": "Line",
"target": {
"file": "goobi-viewer-core/src/main/java/io/goobi/viewer/managedbeans/ActiveDocumentBean.java"
},
"id": "CVE-2023-29014-6f865467",
"deprecated": false
},
{
"digest": {
"length": 245.0,
"function_hash": "131874088341261146231876952172612224211"
},
"signature_version": "v1",
"source": "https://github.com/intranda/goobi-viewer-core/commit/c29efe60e745a94d03debc17681c4950f3917455",
"signature_type": "Function",
"target": {
"function": "setImageToShow",
"file": "goobi-viewer-core/src/main/java/io/goobi/viewer/managedbeans/ActiveDocumentBean.java"
},
"id": "CVE-2023-29014-ed324873",
"deprecated": false
}
]
"2026-07-15T21:12:13Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29014.json"