Description
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.0 or later.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/08/03/3
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-40369
https://lists.apache.org/thread/r2j00nrnpjgcmoxvlv3pgfoq9kzrcsfh
Related Vulnerabilities
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity
CVE-2021-3856 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2021-46036 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-36887 Vulnerability in maven package org.jenkins-ci.plugins:jobconfighistory
CVE-2021-21697 Vulnerability in maven package org.jenkins-ci.main:jenkins-core