OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The application reflects unsanitized user input into the HTML output.
References
Link | Resource |
---|---|
https://www.oracle.com/security-alerts/all-oracle-cves-outside-other-oracle-public-documents.html | Vendor Advisory |
Configurations
History
22 Sep 2025, 14:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Oracle opengrok
Oracle |
|
References | () https://www.oracle.com/security-alerts/all-oracle-cves-outside-other-oracle-public-documents.html - Vendor Advisory | |
CPE | cpe:2.3:a:oracle:opengrok:1.14.1:*:*:*:*:*:*:* |
19 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
19 Sep 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-19 00:15
Updated : 2025-09-22 14:25
NVD link : CVE-2025-30755
Mitre link : CVE-2025-30755
CVE.ORG link : CVE-2025-30755
JSON object : View
Products Affected
oracle
- opengrok
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')