A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2022-06-27T0948 is able to address this issue. The name of the patch is a120c2153e263e62c4db34a06ab96a9f1c6bccb6. It is recommended to upgrade the affected component. The identifier VDB-215885 was assigned to this vulnerability.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-4513.json"
[
{
"digest": {
"length": 61.0,
"function_hash": "291766690054689174007335976283353075022"
},
"source": "https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6",
"target": {
"file": "src/main/java/eionet/cr/web/action/factsheet/FactsheetActionBean.java",
"function": "setUri"
},
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2022-4513-3ddb2cb2",
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"109716919426651240874763354902061270573",
"50971795767043370246865493425822085841",
"43705636024550604102539654960742358331",
"115573468973361860569008290543740021383"
]
},
"source": "https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6",
"target": {
"file": "src/main/java/eionet/cr/web/action/factsheet/FactsheetActionBean.java"
},
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2022-4513-77ed2ea6",
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"44009963968453302676748712366949947276",
"331551094413578595634944611216908208772",
"201387197250488008082750346311107453299",
"72858227104987213436395399215477680001",
"40829780042211735530104363448623988551",
"288130195056198940585807537526708082867",
"174456401461637494251451368174855139381",
"271310014619308501437625874547082334968"
]
},
"source": "https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6",
"target": {
"file": "src/main/java/eionet/cr/web/action/TagSearchActionBean.java"
},
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2022-4513-7a450272",
"signature_version": "v1"
}
]