PT-2023-8929 · Opennms · Opennms Meridian+1

Stefan Schiller

·

Publicado

2023-02-22

·

Atualizado

2023-08-16

·

CVE-2023-0846

CVSS v2.0

7.1

Alta

VetorAV:A/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions OpenNMS Meridian versions prior to 2023.1.0 OpenNMS Horizon versions prior to 31.0.4
Description The issue is related to unauthenticated, stored cross-site scripting in the display of alarm reduction keys, which could allow an attacker to access confidential session information. This is due to inadequate protection of the web page structure. The exploitation of this issue may enable a remote attacker to gain unauthorized access to protected session information.
Recommendations For OpenNMS Meridian versions prior to 2023.1.0, upgrade to Meridian 2023.1.0 or newer. For OpenNMS Horizon versions prior to 31.0.4, upgrade to Horizon 31.0.4. As a temporary workaround, consider restricting access to the alarm reduction keys display to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02652
CVE-2023-0846
GHSA-79JR-8FHM-8WV3

Produtos afetados

Opennms Horizon
Opennms Meridian