PT-2023-16573 · Opennms · Opennms Meridian +1
Published
2023-02-23
·
Updated
2023-03-03
·
CVE-2023-0869
Published
2023-02-23
·
Updated
2023-03-03
·
CVE-2023-0869
6.1
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenNMS Meridian versions prior to 2023.1.0
OpenNMS Horizon versions prior to 31.0.4
Description:
Cross-site scripting in outage/list.htm allows an attacker access to confidential session information. The software is intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Recommendations:
For OpenNMS Meridian versions prior to 2023.1.0, upgrade to Meridian 2023.1.0 or newer.
For OpenNMS Horizon versions prior to 31.0.4, upgrade to Horizon 31.0.4 or newer.
Fix
RCE
XSS