-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description explicitly identifies PrepareExecutionPipelineServlet as the location where unescaped 'id' parameters are included in HTML output. In Java servlet implementations, the doGet method is the standard entry point for handling GET requests. The lack of output escaping for the 'id' parameter when writing HREF attributes would occur in the request handling method of this servlet. While specific line numbers aren't available, the component and parameter are explicitly named in the advisory, making this a high-confidence identification based on standard Java servlet patterns and the vulnerability description.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.hop:hop | maven | < 2.8.0 | 2.8.0 |
Ongoing coverage of React2Shell