CRITICAL10.0
GHSA-cqhr-jqvc-qw9p
Java Melody vulnerable to cross-site scripting
Quick fix
GHSA-cqhr-jqvc-qw9p — net.bull.javamelody:javamelody-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.61.0</version> for net.bull.javamelody:javamelody-coreDetails
JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/net.bull.javamelody:javamelody-core
Introduced in:
0Fixed in: 1.61.0Fix
# pom.xml: bump <version>1.61.0</version> for net.bull.javamelody:javamelody-core