XSS vulnerability in the MVCBean JSP portlet maven archetype
Published Jan 6, 2022
6.1
MEDIUMCVSS 3.1
EPSS 2.33%
Description
The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.
Affected products
-
- Version org.apache.portals.pluto.archetype:mvcbean-jsp-portlet-archetype 3.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Portals | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
If a project was generated from the affected maven archetype using a command like the following:
mvn archetype:generate \ -DarchetypeGroupId=org.apache.portals.pluto.archetype \ -DarchetypeArtifactId=mvcbean-jsp-portlet-archetype \ -DarchetypeVersion=3.1.0 \ -DgroupId=com.mycompany \ -DartifactId=com.mycompany.my.mvcbean.jsp.portlet
Then developers must fix the generated greeting.jspx file by escaping the rendered values submitted to the "First Name" and "Last Name" fields.
For example, change:
<span>${user.firstName} ${user.lastName}! </span>
To:
<span>${mvc.encoders.html(user.firstName)} ${mvc.encoders.html(user.lastName)}! </span>
Moving forward, all such projects should be generated from version 3.1.1 of the Maven archetype.
References (3)
- https://github.com/advisories/GHSA-3qp6-m7hp-jrwf Advisory
- https://lists.apache.org/thread/m5j87nn1lmvzp8b9lmh7gqq68g5lnb7p x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-36739
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-3qp6-m7hp-jrwf | Advisory | |
| https://lists.apache.org/thread/m5j87nn1lmvzp8b9lmh7gqq68g5lnb7p | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-36739 |
Change history (0)
No recorded changes yet.