VDB
Sign up
MEDIUM4.6

GHSA-f7jh-m6wp-jm7f

HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store

Quick fix

GHSA-f7jh-m6wp-jm7f — org.jboss.hal:hal-console: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.7.11.Final</version> for org.jboss.hal:hal-console

Details

A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.

### Impact Cross-site scripting (XSS) vulnerability in the management console.

### Patches Fixed in [HAL 3.7.11.Final](https://github.com/hal/console/releases/tag/v3.7.11)

### Workarounds No workaround available

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jboss.hal:hal-console
Introduced in: 0Fixed in: 3.7.11.Final
Fix# pom.xml: bump <version>3.7.11.Final</version> for org.jboss.hal:hal-console

References