First published: Wed Mar 12 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Felix HTTP Webconsole Plugin | >=1.0<=1.2.0 | |
maven/org.apache.felix:org.apache.felix.http.webconsoleplugin | <1.2.2 | 1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27867 has a medium severity level due to its potential exploitability in Cross-site Scripting attacks.
To fix CVE-2025-27867, users should upgrade to Apache Felix HTTP Webconsole Plugin version 1.2.2 or later.
CVE-2025-27867 affects Apache Felix HTTP Webconsole Plugin versions from 1.0 to 1.2.0.
CVE-2025-27867 is classified as a Cross-site Scripting (XSS) vulnerability resulting from improper neutralization of input.
Any users or organizations using affected versions of the Apache Felix HTTP Webconsole Plugin are at risk from CVE-2025-27867.