Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter.
References
| Link | Resource |
|---|---|
| https://docs.akeles.com/ooo/release-notes-for-4-2-0 | Release Notes |
| https://www.y-security.de | Not Applicable |
Configurations
History
10 Oct 2025, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:akeles:out_of_office_assistant:4.0.1:*:*:*:*:jira:*:* | |
| References | () https://docs.akeles.com/ooo/release-notes-for-4-2-0 - Release Notes | |
| References | () https://www.y-security.de - Not Applicable | |
| First Time |
Akeles out Of Office Assistant
Akeles |
08 Jul 2025, 16:19
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
03 Jul 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-03 15:15
Updated : 2025-10-10 19:32
NVD link : CVE-2025-45938
Mitre link : CVE-2025-45938
CVE.ORG link : CVE-2025-45938
JSON object : View
Products Affected
akeles
- out_of_office_assistant
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
