VYPR
Medium severity6.1NVD Advisory· Published Jan 4, 2018· Updated Jun 17, 2026

CVE-2017-17837

CVE-2017-17837

Description

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.deltaspike.modules:jsf-module-projectMaven
< 1.8.11.8.1

Affected products

3

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.