QID 995458

Date Published: 2023-10-03

QID 995458: Java (Maven) Security Update for org.apache.struts:struts2-dojo-plugin (GHSA-rm26-w253-9qv7)

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Github security advisory GHSA-rm26-w253-9qv7 for updates and patch information.
    Vendor References

    CVEs related to QID 995458

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rm26-w253-9qv7 org.apache.struts:struts2-dojo-plugin URL Logo github.com/advisories/GHSA-rm26-w253-9qv7