First published: Fri May 02 2025(Updated: )
OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens through improper handling of path segments. The application reflects unsanitized user input into the HTML output.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenGrok |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-21572 is considered a high severity vulnerability due to its nature of allowing reflected Cross-Site Scripting (XSS).
CVE-2025-21572 affects OpenGrok by improperly handling path segments, allowing attackers to inject unsanitized JavaScript code into the application's HTML output.
To fix CVE-2025-21572, ensure that OpenGrok is updated to the latest version where this XSS vulnerability is patched.
CVE-2025-21572 affects OpenGrok version 1.13.25 and possibly earlier versions that do not have the XSS vulnerability resolved.
If using an affected version of OpenGrok, immediately update to a patched version and review your application's security configurations.