Description
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.0 or later.
Remediation
References
https://lists.apache.org/thread/r2j00nrnpjgcmoxvlv3pgfoq9kzrcsfh
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-40369
http://www.openwall.com/lists/oss-security/2022/08/03/3
Related Vulnerabilities
CVE-2020-7015 Vulnerability in npm package kibana
CVE-2017-1000388 Vulnerability in maven package org.jenkins-ci.plugins:depgraph-view
CVE-2021-21631 Vulnerability in maven package org.jenkins-ci.plugins:cloud-stats
CVE-2021-4040 Vulnerability in maven package org.apache.activemq:artemis-core-client
CVE-2023-1108 Vulnerability in maven package io.undertow:undertow-core