{"id":"CVE-2017-17837","details":"The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.","aliases":["GHSA-4q23-g7mf-xp98"],"modified":"2026-07-08T11:35:46.770893Z","published":"2018-01-04T15:29:00.240Z","references":[{"type":"WEB","url":"https://git-wip-us.apache.org/repos/asf?p=deltaspike.git%3Bh=4e25023"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r17b326c0eb35d8c71c84c171eda83e3e1f011dc757781e34f2846018%40%3Cdev.deltaspike.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r78565f0f4ecb4ad32a6c405b45b9ee568dfc4729ba63e7d7cb6adf88%40%3Cdev.deltaspike.apache.org%3E"},{"type":"FIX","url":"https://issues.apache.org/jira/browse/DELTASPIKE-1307"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/deltaspike","events":[{"introduced":"2d4e4099852ffbd6aec1aca73dda331cf5329d91"},{"last_affected":"2d4e4099852ffbd6aec1aca73dda331cf5329d91"}],"database_specific":{"cpe":"cpe:2.3:a:apache:deltaspike:1.8.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.8.0"},{"last_affected":"1.8.0"}],"source":"CPE_STRING"}}],"versions":["1.8.0","deltaspike-1.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17837.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}