VYPR
Medium severity6.1NVD Advisory· Published Oct 19, 2022· Updated Jun 17, 2026

CVE-2022-42466

CVE-2022-42466

Description

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings are properly escaped when rendered.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.isis.core:isis-coreMaven
< 2.0.0-M92.0.0-M9

Affected products

11
  • Apache/Isis9 versions
    cpe:2.3:a:apache:isis:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:apache:isis:*:*:*:*:*:*:*:*range: <2.0.0
    • cpe:2.3:a:apache:isis:2.0.0:milestone1:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone2:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone3:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone4:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone5:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone6:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone7:*:*:*:*:*:*
    • cpe:2.3:a:apache:isis:2.0.0:milestone8:*:*:*:*:*:*
  • ghsa-coords
    Range: < 2.0.0-M9
  • Apache/Apachecpe-rescue
    Range: unspecified

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.