CVE-2023-0867: Multiple stored and reflected Cross-site Scripting in webapp
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0867?
The severity of CVE-2023-0867 is medium with a severity value of 6.1.
How can an attacker exploit CVE-2023-0867?
An attacker can exploit CVE-2023-0867 by leveraging stored and reflected cross-site scripting vulnerabilities in webapp JSP pages in OpenNMS Meridian and Horizon to gain access to confidential session information.
Which versions of OpenNMS Meridian are affected by CVE-2023-0867?
Versions of OpenNMS Meridian up to and excluding 2023.1.0 are affected by CVE-2023-0867.
Which versions of OpenNMS Horizon are affected by CVE-2023-0867?
Versions of OpenNMS Horizon up to and excluding 31.0.4 are affected by CVE-2023-0867.
How can I fix CVE-2023-0867?
To fix CVE-2023-0867, users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.