Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS02Znh2LTM4eGMtaDg2Ns2_iQ
Apache Jackrabbit contains Cross-site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
Permalink: https://github.com/advisories/GHSA-6fxv-38xc-h866JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Znh2LTM4eGMtaDg2Ns2_iQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: over 1 year ago
Identifiers: GHSA-6fxv-38xc-h866, CVE-2009-0026
References:
- https://nvd.nist.gov/vuln/detail/CVE-2009-0026
- https://issues.apache.org/jira/browse/JCR-1925
- https://github.com/apache/jackrabbit/commit/36330ae8df40ceaddf9f3f95b8d4855b54921579
- https://github.com/apache/jackrabbit/commit/fbdcc02bc35db1d23b527da7bc411087ef29bf1f
- https://access.redhat.com/security/cve/CVE-2009-0026
- https://bugzilla.redhat.com/show_bug.cgi?id=481126
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48110
- https://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt
- https://www.vupen.com/english/advisories/2009/0177
- https://github.com/advisories/GHSA-6fxv-38xc-h866
Blast Radius: 0.0
Affected Packages
maven:org.apache.jackrabbit:jackrabbit
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: < 1.5.2
Fixed in: 1.5.2
All affected versions: 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.3, 1.5.0
All unaffected versions: 1.5.6, 1.6.1, 1.6.2, 1.6.4, 1.6.5