PT-2021-16863 · Opennms · Opennms Horizon+1

Published

2021-05-20

·

Updated

2021-05-26

·

CVE-2021-25933

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenNMS Horizon versions opennms-1-0-stable through opennms-27.1.0-1 OpenNMS Meridian versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1 OpenNMS Meridian versions meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1
Description The issue is related to Stored Cross-Site Scripting. The function validateFormInput() performs improper validation checks on the input sent to the groupName and groupComment parameters. Due to this flaw, an authenticated attacker could inject arbitrary script and trick other admin users into downloading malicious files, which can cause severe damage to the organization using OpenNMS.
Recommendations For OpenNMS Horizon versions opennms-1-0-stable through opennms-27.1.0-1, update to a version later than opennms-27.1.0-1. For OpenNMS Meridian versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1, update to a version later than meridian-foundation-2019.1.18-1. For OpenNMS Meridian versions meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1, update to a version later than meridian-foundation-2020.1.6-1. As a temporary workaround, consider disabling the validateFormInput() function until a patch is available. Restrict access to the groupName and groupComment parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25933
GHSA-JJHW-5MXP-2G2Q

Affected Products

Opennms Horizon
Opennms Meridian