Description
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact
Remediation
References
https://lists.apache.org/thread/11j19v1gjsk7o6o8nch1xrydow9b8lll
Related Vulnerabilities
CVE-2022-34189 Vulnerability in maven package org.jenkins-ci.plugins:image-tag-parameter
CVE-2015-8795 Vulnerability in maven package org.apache.solr:solr
CVE-2015-5175 Vulnerability in maven package org.apache.cxf.fediz:fediz-core
CVE-2019-12423 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-jose
CVE-2016-0793 Vulnerability in maven package org.wildfly:wildfly-undertow