VDB
Sign up
MEDIUM

GHSA-64gp-r758-8pfm

Cross Site Scripting (XSS) vulnerability while uploading content to a new deployment

Quick fix

GHSA-64gp-r758-8pfm — org.jboss.hal:hal-console: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.7.7.Final</version> for org.jboss.hal:hal-console

Details

A vulnerability was found in the WildFly management console. A user may perform cross-site scripting in the deployment system. An attacker (or insider) may execute a malicious payload which could trigger an undesired behavior against the server.

### Impact Cross-site scripting (XSS) vulnerability in the management console.

### Patches Fixed in [HAL 3.7.7.Final](https://github.com/hal/console/releases/tag/v3.7.7)

### Workarounds No workaround available

### References See also: https://issues.redhat.com/browse/WFLY-19969

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jboss.hal:hal-console
Introduced in: 0Fixed in: 3.7.7.Final
Fix# pom.xml: bump <version>3.7.7.Final</version> for org.jboss.hal:hal-console

References