VDB
Sign up
MEDIUM

GHSA-p4mx-p49m-8rw4

Improper Neutralization of Input During Web Page Generation in JavaMelody

Quick fix

GHSA-p4mx-p49m-8rw4 — net.bull.javamelody:javamelody-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.47.0</version> for net.bull.javamelody:javamelody-core

Details

Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/net.bull.javamelody:javamelody-core
Introduced in: 0Fixed in: 1.47.0
Fix# pom.xml: bump <version>1.47.0</version> for net.bull.javamelody:javamelody-core

References