VDB
Sign up
CRITICAL10.0

GHSA-cqhr-jqvc-qw9p

Java Melody vulnerable to cross-site scripting

Quick fix

GHSA-cqhr-jqvc-qw9p — net.bull.javamelody:javamelody-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.61.0</version> for net.bull.javamelody:javamelody-core

Details

JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/net.bull.javamelody:javamelody-core
Introduced in: 0Fixed in: 1.61.0
Fix# pom.xml: bump <version>1.61.0</version> for net.bull.javamelody:javamelody-core

References