First published: Mon Feb 10 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.felix:org.apache.felix.webconsole | >=5.0.0<5.0.10 | 5.0.10 |
maven/org.apache.felix:org.apache.felix.webconsole | >=4.0.0<4.9.10 | 4.9.10 |
Apache Felix Web Console | <=4.9.8<=5.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25247 is classified as a moderate severity vulnerability.
To fix CVE-2025-25247, upgrade Apache Felix Webconsole to version 4.9.10, 5.0.10, or higher.
CVE-2025-25247 affects Apache Felix Webconsole versions 4.x up to 4.9.8 and 5.x up to 5.0.8.
CVE-2025-25247 is an improper neutralization of input during web page generation, commonly known as a Cross-site Scripting (XSS) vulnerability.
It is not recommended to continue using affected versions of Apache Felix Webconsole due to the potential XSS risk posed by CVE-2025-25247.