Description
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.0 or later.
Remediation
References
https://lists.apache.org/thread/r2j00nrnpjgcmoxvlv3pgfoq9kzrcsfh
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-40369
http://www.openwall.com/lists/oss-security/2022/08/03/3
Related Vulnerabilities
CVE-2018-12536 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2023-34981 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-1354 Vulnerability in npm package nodegit
CVE-2019-10411 Vulnerability in maven package com.inedo.buildmaster:inedo-buildmaster
CVE-2023-30521 Vulnerability in maven package org.jenkins-ci.plugins:assembla-merge-request-builder