{"id":"CVE-2019-12416","aliases":["GHSA-rhg5-fqr3-hrf5"],"url":"https://o3.security/vulnerability/CVE-2019-12416","summary":"Injection in DeltaSpike","details":"we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.","published":"2020-03-19T15:15:12.933Z","modified":"2026-07-08T18:18:03.889542Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.deltaspike:deltaspike","fixedVersion":"1.9.4"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r848d7d4c0bf637da55f01103eb8ba0fce344c295fda53264cbaa1568%40%3Ccommits.camel.apache.org%3E"},{"type":"EVIDENCE","url":"https://lists.apache.org/thread.html/r8f327712b2b07f867fde1e77cbafcf8cc6a3facaa693ffdd2c3285e3%40%3Cdev.deltaspike.apache.org%3E"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T18:18:03.889542Z"}}