GHSA-c372-x57p-6x7v

Suggest an improvement
Source
https://github.com/advisories/GHSA-c372-x57p-6x7v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c372-x57p-6x7v/GHSA-c372-x57p-6x7v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c372-x57p-6x7v
Aliases
  • CVE-2009-0038
Published
2022-05-02T03:12:29Z
Modified
2024-12-03T06:03:41.086365Z
Summary
Apache Geronimo Application Server multiple cross-site scripting (XSS) vulnerabilities
Details

Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.

Database specific
{
    "nvd_published_at": "2009-04-17T14:30:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-26T22:18:01Z"
}
References

Affected packages

Maven / org.apache.geronimo.plugins:console

Package

Name
org.apache.geronimo.plugins:console
View open source insights on deps.dev
Purl
pkg:maven/org.apache.geronimo.plugins/console

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Fixed
2.1.4

Affected versions

2.*

2.1
2.1.1
2.1.2
2.1.3