VYPR
Moderate severityNVD Advisory· Published Jul 25, 2023· Updated Feb 13, 2025

Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole plugin

CVE-2023-38435

Description

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.

Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.felix:org.apache.felix.healthcheck.webconsolepluginMaven
< 2.1.02.1.0

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.