CVE-2023-38435: Apache Felix Health Check Webconsole Plugin

Medium severity, CVSS 6.1. EPSS: 2.2% chance of exploitation in the next 30 days.

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

Affected products

  • Apache Felix Health Check Webconsole Plugin: before 2.1.0 (fixed in 2.1.0)

Published 2023-07-25. Last modified 2026-06-17.