First published: Tue Jul 25 2023(Updated: )
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.felix:org.apache.felix.healthcheck.webconsoleplugin | <2.1.0 | 2.1.0 |
Apache Felix Health Checks | <=2.0.2 | |
Apache Felix Health Check Webconsole Plugin | <2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38435 is a vulnerability in the Apache Felix Healthcheck Webconsole Plugin that allows for a reflected cross-site scripting (XSS) attack.
CVE-2023-38435 has a severity level of medium with a CVSS score of 6.1.
CVE-2023-38435 affects the Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior.
To fix CVE-2023-38435, upgrade to Apache Felix Healthcheck Webconsole Plugin version 2.1.0 or higher.
For more information about CVE-2023-38435, you can refer to the NIST vulnerability database at https://nvd.nist.gov/vuln/detail/CVE-2023-38435.