PT-2023-26420 · Apache · Apache Felix Healthcheck Webconsole Plugin

Published

2023-07-25

·

Updated

2023-12-13

·

CVE-2023-38435

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Felix Healthcheck Webconsole Plugin versions 2.0.2 and prior
Description An improper neutralization of input during web page generation, also known as Cross-site Scripting, may allow an attacker to perform a reflected cross-site scripting (XSS) attack. This issue is related to the Apache Felix Healthcheck Webconsole Plugin.
Recommendations Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-38435
GHSA-4PVW-G9FX-594R

Affected Products

Apache Felix Healthcheck Webconsole Plugin