PT-2022-10542 · Apache · Apache Pluto

Neil Griffin

·

Published

2022-01-06

·

Updated

2022-01-12

·

CVE-2021-36739

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Pluto version 3.1.0
Description The issue concerns Cross-Site Scripting (XSS) attacks, which occur when an attacker injects malicious code into a website, allowing them to steal user data or take control of the user's session. In this case, the first name and last name fields of the Apache Pluto MVCBean JSP portlet maven archetype are vulnerable to such attacks.
Recommendations For Apache Pluto version 3.1.0, consider validating and sanitizing user input for the first name and last name fields to prevent XSS attacks. As a temporary workaround, restrict user input to only allow expected characters and formats for these fields until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36739
GHSA-3QP6-M7HP-JRWF

Affected Products

Apache Pluto