CVE-2025-23366 – org.jboss.hal:hal-console
Package
Manager: maven
Name: org.jboss.hal:hal-console
Vulnerable Version: >=0 <3.7.7.final
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00034 pctl0.08144
Details
HAL Console has a Cross Site Scripting (XSS) vulnerability of user input A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”. ### Impact Cross-site scripting (XSS) vulnerability in the management console. ### Patches Fixed in [HAL 3.7.7.Final](https://github.com/hal/console/releases/tag/v3.7.7) ### Workarounds No workaround available ### References - https://access.redhat.com/security/cve/CVE-2025-23366 - https://bugzilla.redhat.com/show_bug.cgi?id=2337619
Metadata
Created: 2025-01-16T19:05:39Z
Modified: 2025-01-16T19:05:39Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-jhvj-f397-8w6q/GHSA-jhvj-f397-8w6q.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-jhvj-f397-8w6q
Finding: F425
Auto approve: 1