GHSA-fh63-4r66-jc7v

Suggest an improvement
Source
https://github.com/advisories/GHSA-fh63-4r66-jc7v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-fh63-4r66-jc7v/GHSA-fh63-4r66-jc7v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fh63-4r66-jc7v
Aliases
Published
2021-03-12T20:24:22Z
Modified
2023-11-08T04:02:24.445339Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Cross-site scripting (XSS) in Apache Velocity Tools
Details

The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary JavaScript in the context of the attacked website and the attacked user. This can be abused to steal session cookies, perform requests in the name of the victim or for phishing attacks.

Database specific
{
    "nvd_published_at": "2021-03-10T08:15:00Z",
    "github_reviewed_at": "2021-03-12T20:23:42Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Maven / org.apache.velocity.tools:velocity-tools-parent

Package

Name
org.apache.velocity.tools:velocity-tools-parent
View open source insights on deps.dev
Purl
pkg:maven/org.apache.velocity.tools/velocity-tools-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1

Affected versions

3.*

3.0

Maven / org.apache.velocity:velocity-tools

Package

Name
org.apache.velocity:velocity-tools
View open source insights on deps.dev
Purl
pkg:maven/org.apache.velocity/velocity-tools

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0

Affected versions

1.*

1.3

2.*

2.0-beta2
2.0-beta3
2.0-beta4
2.0