Lucene search

K
cvelistOpenNMSCVELIST:CVE-2023-0846
HistoryFeb 22, 2023 - 6:35 p.m.

CVE-2023-0846 Unauthenticated, stored XSS in display of alarm reduction-key

2023-02-2218:35:19
CWE-79
OpenNMS
www.cve.org
2
cve-2023-0846
unauthenticated
stored xss
alarm reduction-key
opennms horizon
opennms meridian
confidential session information
upgrade
installation instructions

CVSS3

6.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

34.2%

Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users
should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and
Horizon installation instructions state that they are intended for installation
within an organization’s private networks and should not be directly accessible
from the Internet.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "Alarm detail"
    ],
    "platforms": [
      "Windows",
      "Linux",
      "MacOS"
    ],
    "product": "Horizon",
    "repo": "https://github.com/OpenNMS",
    "vendor": "The OpenNMS Group ",
    "versions": [
      {
        "lessThan": "31.0.4",
        "status": "affected",
        "version": "26.1.0",
        "versionType": "git"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Alarm detail"
    ],
    "platforms": [
      "Windows",
      "MacOS",
      "Linux"
    ],
    "product": "Meridian",
    "repo": "https://github.com/OpenNMS",
    "vendor": "The OpenNMS Group",
    "versions": [
      {
        "lessThan": "2020.1.32",
        "status": "affected",
        "version": "2020.1.0",
        "versionType": "git"
      },
      {
        "lessThan": "2021.1.24",
        "status": "affected",
        "version": "2021.1.0",
        "versionType": "git"
      },
      {
        "lessThan": "2022.1.13",
        "status": "affected",
        "version": "2022.1.0",
        "versionType": "git"
      },
      {
        "status": "unaffected",
        "version": "2023.1.0"
      }
    ]
  }
]

CVSS3

6.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

34.2%

Related for CVELIST:CVE-2023-0846