Description
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact
Remediation
References
https://lists.apache.org/thread/x7kt47bf358x8sg9qg02zt0dmdrtow25
Related Vulnerabilities
CVE-2023-33943 Vulnerability in maven package com.liferay:com.liferay.account.admin.web
CVE-2021-21295 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2023-24997 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2019-10403 Vulnerability in maven package org.jenkins-ci.main:jenkins-core