PT-2021-22880 · Apache · Apache Jspwiki

Map1E

·

Published

2021-11-24

·

Updated

2022-11-09

·

CVE-2021-40369

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache JSPWiki versions prior to 2.11.0
Description A carefully crafted plugin link invocation could trigger an issue on Apache JSPWiki, related to the Denounce plugin, allowing the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Recommendations For versions prior to 2.11.0, upgrade to 2.11.0 or later. As a temporary workaround, consider restricting the use of the Denounce plugin until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-40369
GHSA-CFQJ-9G2G-W7Q6

Affected Products

Apache Jspwiki