Medium severity6.1NVD Advisory· Published Jan 4, 2018· Updated Jun 17, 2026
CVE-2017-17837
CVE-2017-17837
Description
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.deltaspike.modules:jsf-module-projectMaven | < 1.8.1 | 1.8.1 |
Affected products
3cpe:2.3:a:apache:deltaspike:1.8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:deltaspike:1.8.0:*:*:*:*:*:*:*
- (no CPE)range: 1.8.0
Patches
Vulnerability mechanics
References
10- issues.apache.org/jira/browse/DELTASPIKE-1307nvdExploitIssue TrackingPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-4q23-g7mf-xp98ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-17837ghsaADVISORY
- git-wip-us.apache.org/repos/asfghsaWEB
- github.com/apache/deltaspike/commit/4e2502358526b944fc5514c206d306e97ff271bbghsaWEB
- lists.apache.org/thread.html/r17b326c0eb35d8c71c84c171eda83e3e1f011dc757781e34f2846018@%3Cdev.deltaspike.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r78565f0f4ecb4ad32a6c405b45b9ee568dfc4729ba63e7d7cb6adf88@%3Cdev.deltaspike.apache.org%3EghsaWEB
- git-wip-us.apache.org/repos/asfnvd
- lists.apache.org/thread.html/r17b326c0eb35d8c71c84c171eda83e3e1f011dc757781e34f2846018%40%3Cdev.deltaspike.apache.org%3Envd
- lists.apache.org/thread.html/r78565f0f4ecb4ad32a6c405b45b9ee568dfc4729ba63e7d7cb6adf88%40%3Cdev.deltaspike.apache.org%3Envd
News mentions
0No linked articles in our index yet.