QID 980465
QID 980465: Java (maven) Security Update for org.opencrx:opencrx-gradle (GHSA-rwh9-8xx8-4wfm)
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rwh9-8xx8-4wfm for updates pertaining to this vulnerability.
Vendor References
- GHSA-rwh9-8xx8-4wfm -
github.com/advisories/GHSA-rwh9-8xx8-4wfm
CVEs related to QID 980465
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rwh9-8xx8-4wfm | org.opencrx:opencrx-client |
|
|
| GHSA-rwh9-8xx8-4wfm | org.opencrx:opencrx-core |
|
|
| GHSA-rwh9-8xx8-4wfm | org.opencrx:opencrx-core-config |
|
|
| GHSA-rwh9-8xx8-4wfm | org.opencrx:opencrx-core-models |
|
|
| GHSA-rwh9-8xx8-4wfm | org.opencrx:opencrx-gradle |
|