GHSA-mjq8-gg9x-87gr

Suggest an improvement
Source
https://github.com/advisories/GHSA-mjq8-gg9x-87gr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mjq8-gg9x-87gr/GHSA-mjq8-gg9x-87gr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-mjq8-gg9x-87gr
Aliases
Published
2024-03-18T09:30:31Z
Modified
2025-03-21T23:17:21.770720Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
FitNesse Cross-site Scripting vulnerability
Details

Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter.

Database specific
{
    "nvd_published_at": "2024-03-18T08:15:06Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-21T22:28:56Z"
}
References

Affected packages

Maven / org.fitnesse:fitnesse

Package

Name
org.fitnesse:fitnesse
View open source insights on deps.dev
Purl
pkg:maven/org.fitnesse/fitnesse

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20220319

Affected versions

Other

20050731
20060719
20070619
20080702
20080812
20081201
20111025
20121220
20130530
20130531
20131109
20131110
20140201
20140418
20140623
20140630
20140901
20150114
20150226
20150424
20150814
20151230
20160515
20160618
20161106
20171210
20171212
20180127
20181221
20181223
20181224
20190110
20190118
20190119
20190127
20190202
20190216
20190224
20190406
20190409
20190416
20190417
20190418
20190421
20190428
20190508
20190620
20190628
20190716
20191110
20191217
20191229
20200108
20200128
20200205
20200304
20200307
20200308
20200404
20200501
20201213
20210410
20210516
20210605
20210606
20211006
20211030