PT-2023-27374 · Opennms · Meridian+1

Publicado

2023-08-14

·

Atualizado

2023-08-23

·

CVE-2023-40311

CVSS v3.1

6.7

Média

VetorAV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenMNS Horizon versions 31.0.8 through 32.0.2
Description Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon. This allows an attacker to store malicious data on the database and then load it on JSPs or Angular templates. The installation instructions for Meridian and Horizon state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Jordi Miralles Comins for reporting this issue.
Recommendations To resolve the issue, upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. As a temporary workaround, consider restricting access to the vulnerable JSP files until a patch is available. Restrict access to the database to minimize the risk of exploitation. Avoid using unsanitized parameters in JSP files until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40311
GHSA-QFW7-PFXX-H9Q2

Produtos afetados

Meridian
Opennms Horizon