Back

MEDIUM

DeltaSpike: XSS injection vulnerability in windowId handling

Published Jan 4, 2018

Description

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 4, 2018
Updated Sep 17, 2024
Reserved Dec 22, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 20, 2017
GHSA-4Q23-G7MF-XP98