Intel

AIKIDO-2025-10210

feign-bom is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 7, 2025

42

Medium Risk

This Affects:

JAVAfeign-bom
10.2.0 - 13.5
Fixed in 13.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to multiple cross-site scripting (XSS) attacks due to insufficient sanitization of user-supplied input, allowing attackers to inject and execute arbitrary scripts in the context of the application.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

feign-bom is vulnerable to Cross-site Scripting (XSS) in versions 10.2.0 - 13.5.

How to fix this

Upgrade the io.github.openfeign:feign-bom library to a patch version.