JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.
{
"severity": "CRITICAL",
"nvd_published_at": null,
"github_reviewed": true,
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2022-07-20T01:36:35Z"
}