PT-2023-16571 · Opennms · Opennms Meridian+1
Baharuddin Zulkifli
·
Published
2023-02-23
·
Updated
2023-03-03
·
CVE-2023-0867
CVSS v3.1
6.7
Medium
| Vector | AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenNMS Meridian versions prior to 2023.1.0
OpenNMS Horizon versions prior to 31.0.4
Description
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages could allow an attacker access to confidential session information.
Recommendations
For OpenNMS Meridian versions prior to 2023.1.0, upgrade to Meridian 2023.1.0 or newer.
For OpenNMS Horizon versions prior to 31.0.4, upgrade to Horizon 31.0.4.
As a temporary workaround, consider restricting access to the webapp jsp pages until a patch is available.
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opennms Horizon
Opennms Meridian