Back

MEDIUM

XSS in V3 Demo Portlet

Published Jan 6, 2022

Description

The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact

Affected products

Remediation

Vendor solution

* Uninstall the v3-demo-portlet.war artifact -or- * Migrate to version 3.1.1 of the v3-demo-portlet.war artifact

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 6, 2022
Updated Aug 4, 2024
Reserved Jul 14, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-X588-G38J-F672