An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.

Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

Project Subscriptions

Vendors Products
Felix Health Check Webconsole Plugin Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4pvw-g9fx-594r Cross-site Scripting in healthcheck webconsole plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00924}

epss

{'score': 0.01205}


Thu, 13 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher. An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-13T17:01:51.002Z

Reserved: 2023-07-18T03:54:02.288Z

Link: CVE-2023-38435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-25T16:15:11.500

Modified: 2025-02-13T17:16:47.610

Link: CVE-2023-38435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses