Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Http Apache Jetspeed | — | Upgrade Apache Jetspeed-2 to version 2.3.1 or later, which is the final release of the project and contains the fixes for the 2016 security advisories. Note that Apache Jetspeed-2 has been declared dormant (2022) and retired to the Apache Attic (2025), so 2.3.1 is the highest version that will ever ship; migration to a supported portal framework should be considered. | Jun 12, 2026 | Apr 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub