Apache Struts Dojo Plugin XSS Vulnerability

Description

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2022-05-01 18:45:52 UTC
Updated
2023-09-22 21:55:25 UTC
GitHub reviewed
2023-09-22 21:55:23 UTC
NVD published
2009-04-09

EPSS Score

Score Percentile
1.75% 82.52%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven org.apache.struts:struts2-dojo-plugin >= 0.4.1, <= 0.4.2 0.4.3

References

cvelogic Threat Intelligence