VYPR
Moderate severityNVD Advisory· Published Mar 12, 2025· Updated Mar 21, 2025

Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin

CVE-2025-27867

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin.

This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0.

Users are recommended to upgrade to version 1.2.2, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.felix:org.apache.felix.http.webconsolepluginMaven
< 1.2.21.2.2

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.