org.opennms:opennms-webapp
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.opennms:opennms-webapppage 1 of 1
- CVE-2023-0868MEDIUMCVSS 6.7EG 6.7✓ Fixed in 31.0.42023-02-23
Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian …
- CVE-2023-0870HIGHCVSS 8.1EG 8.1✓ Fixed in 31.0.62023-03-22
A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to …
- CVE-2023-40311MEDIUMCVSS 6.7EG 6.7✓ Fixed in 32.0.22023-08-14
Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that allow an attacker to store on database and then load on JSPs or Angular…
- CVE-2023-40312MEDIUMCVSS 6.7EG 6.7✓ Fixed in 32.0.22023-08-14
Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that an attacker can modify to craft a malicious XSS payload. The soluti…
- CVE-2023-40314MEDIUMCVSS 5.8EG 5.8✓ Fixed in 32.0.52023-11-16
Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Horizon 32.0.5 or newer and Meridian 2023.1.9 or new…
Check whether org.opennms:opennms-webapp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.opennms:opennms-webapp CVEs against the assets you own.
Start Free Scan →