Description
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2424 | The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1. |
Github GHSA |
GHSA-4q23-g7mf-xp98 | Cross-site Scripting in Apache DeltaSpike |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T02:21:15.482Z
Reserved: 2017-12-22T00:00:00.000Z
Link: CVE-2017-17837
No data.
Status : Modified
Published: 2018-01-04T15:29:00.240
Modified: 2024-11-21T03:18:47.200
Link: CVE-2017-17837
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA