First published: Thu Feb 23 2023(Updated: )
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Credit: security@opennms.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenNMS Horizon | <31.0.4 | |
OpenNMS Meridian | <2023.1.0 |
Upgrade to a newer version of Meridian or Horizon.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0867 is medium with a severity value of 6.1.
An attacker can exploit CVE-2023-0867 by leveraging stored and reflected cross-site scripting vulnerabilities in webapp JSP pages in OpenNMS Meridian and Horizon to gain access to confidential session information.
Versions of OpenNMS Meridian up to and excluding 2023.1.0 are affected by CVE-2023-0867.
Versions of OpenNMS Horizon up to and excluding 31.0.4 are affected by CVE-2023-0867.
To fix CVE-2023-0867, users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.