CVE-2013-4378

medium
Published 2013-09-30 ยท Modified 2024-12-03
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

Improper Neutralization of Input During Web Page Generation in JavaMelody

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Package impact

EcosystemPackageVulnerableFixed
java Mavennet.bull.javamelody:javamelody-core<1.47.01.47.0

Application impact

VendorProductVersionsFixed
emeric_vernatjavamelody{"endIncluding":"1.46"}
emeric_vernatjavamelody1.6
emeric_vernatjavamelody1.7
emeric_vernatjavamelody1.8
emeric_vernatjavamelody1.9
emeric_vernatjavamelody1.10
emeric_vernatjavamelody1.11
emeric_vernatjavamelody1.12
emeric_vernatjavamelody1.13
emeric_vernatjavamelody1.14
emeric_vernatjavamelody1.15
emeric_vernatjavamelody1.16
emeric_vernatjavamelody1.17
emeric_vernatjavamelody1.18
emeric_vernatjavamelody1.19
emeric_vernatjavamelody1.20
emeric_vernatjavamelody1.21
emeric_vernatjavamelody1.22
emeric_vernatjavamelody1.23
emeric_vernatjavamelody1.24
emeric_vernatjavamelody1.25
emeric_vernatjavamelody1.26
emeric_vernatjavamelody1.27
emeric_vernatjavamelody1.28
emeric_vernatjavamelody1.29
emeric_vernatjavamelody1.30
emeric_vernatjavamelody1.31
emeric_vernatjavamelody1.32
emeric_vernatjavamelody1.32.1
emeric_vernatjavamelody1.33
emeric_vernatjavamelody1.34
emeric_vernatjavamelody1.35
emeric_vernatjavamelody1.36
emeric_vernatjavamelody1.37
emeric_vernatjavamelody1.38
emeric_vernatjavamelody1.39
emeric_vernatjavamelody1.40
emeric_vernatjavamelody1.41
emeric_vernatjavamelody1.42
emeric_vernatjavamelody1.43
emeric_vernatjavamelody1.44
emeric_vernatjavamelody1.45

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.