PT-2023-16571 · Opennms · Opennms Meridian+1

Baharuddin Zulkifli

·

Publicado

2023-02-23

·

Atualizado

2023-03-03

·

CVE-2023-0867

CVSS v3.1

6.7

Média

VetorAV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenNMS Meridian versions prior to 2023.1.0 OpenNMS Horizon versions prior to 31.0.4
Description Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages could allow an attacker access to confidential session information.
Recommendations For OpenNMS Meridian versions prior to 2023.1.0, upgrade to Meridian 2023.1.0 or newer. For OpenNMS Horizon versions prior to 31.0.4, upgrade to Horizon 31.0.4. As a temporary workaround, consider restricting access to the webapp jsp pages until a patch is available.

Correção

RCE

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0867
GHSA-MJV2-6JV4-VRG7

Produtos afetados

Opennms Horizon
Opennms Meridian