{"id":"GHSA-4q23-g7mf-xp98","summary":"Cross-site Scripting in Apache DeltaSpike","details":"The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.","aliases":["CVE-2017-17837"],"modified":"2023-11-08T03:59:14.951489Z","published":"2022-05-13T01:02:10Z","database_specific":{"github_reviewed_at":"2022-11-03T23:21:05Z","nvd_published_at":"2018-01-04T15:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-17837"},{"type":"WEB","url":"https://github.com/apache/deltaspike/commit/4e2502358526b944fc5514c206d306e97ff271bb"},{"type":"WEB","url":"https://git-wip-us.apache.org/repos/asf?p=deltaspike.git;h=4e25023"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/DELTASPIKE-1307"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r17b326c0eb35d8c71c84c171eda83e3e1f011dc757781e34f2846018@%3Cdev.deltaspike.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r78565f0f4ecb4ad32a6c405b45b9ee568dfc4729ba63e7d7cb6adf88@%3Cdev.deltaspike.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.deltaspike.modules:jsf-module-project","ecosystem":"Maven","purl":"pkg:maven/org.apache.deltaspike.modules/jsf-module-project"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.1"}]}],"versions":["0.4","0.5","0.6","0.7","1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.2.0","1.2.1","1.3.0","1.4.0","1.4.1","1.4.2","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.6.0","1.6.1","1.7.0","1.7.1","1.7.2","1.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4q23-g7mf-xp98/GHSA-4q23-g7mf-xp98.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}