PT-2023-16573 · Opennms · Opennms Meridian +1

Published

2023-02-23

·

Updated

2023-03-03

·

CVE-2023-0869

CVSS v3.1
6.1
VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

OpenNMS Meridian versions prior to 2023.1.0

OpenNMS Horizon versions prior to 31.0.4

Description:

Cross-site scripting in outage/list.htm allows an attacker access to confidential session information. The software is intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Recommendations:

For OpenNMS Meridian versions prior to 2023.1.0, upgrade to Meridian 2023.1.0 or newer.

For OpenNMS Horizon versions prior to 31.0.4, upgrade to Horizon 31.0.4 or newer.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-0869
GHSA-7V39-JJJ6-J4J4

Affected Products

Opennms Horizon
Opennms Meridian