GHSA-4c37-7m5h-c8m9

Suggest an improvement
Source
https://github.com/advisories/GHSA-4c37-7m5h-c8m9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4c37-7m5h-c8m9
Aliases
Published
2025-02-10T12:30:45Z
Modified
2025-02-10T18:42:16Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Apache Felix Webconsole: XSS in services console
Details

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.

This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8.

Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-02-10T18:08:47Z",
    "nvd_published_at":  "2025-02-10T12:15:29Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.apache.felix:org.apache.felix.webconsole

Package

Name
org.apache.felix:org.apache.felix.webconsole
View open source insights on deps.dev
Purl
pkg:maven/org.apache.felix/org.apache.felix.webconsole

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.9.10

Affected versions

4.*
4.0.0
4.2.0
4.2.2
4.2.4
4.2.6
4.2.8
4.2.10
4.2.12
4.2.14
4.2.16
4.2.18
4.3.0
4.3.2
4.3.4
4.3.8
4.3.10
4.3.12
4.3.14
4.3.16
4.4.0
4.5.0
4.5.2
4.5.4
4.6.0
4.6.2
4.6.4
4.7.0
4.7.2
4.8.0
4.8.2
4.8.4
4.8.8
4.8.10
4.8.12
4.9.0
4.9.2
4.9.4
4.9.6
4.9.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json"

Maven / org.apache.felix:org.apache.felix.webconsole

Package

Name
org.apache.felix:org.apache.felix.webconsole
View open source insights on deps.dev
Purl
pkg:maven/org.apache.felix/org.apache.felix.webconsole

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.0.10

Affected versions

5.*
5.0.0
5.0.2
5.0.4
5.0.6
5.0.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json"