Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache DeltaSpike-JSF 跨站脚本漏洞
Vulnerability Description
Apache DeltaSpike是美国阿帕奇(Apache)软件基金会所研发的一套CDI可移植扩展框架。JSF是其中的一个提供与JSF的CDI集成的模块。 Apache DeltaSpike-JSF 1.8.0版本中的windowId处理存在跨站脚本漏洞。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A