# The remote web server is affected by a cross-site scripting vulnerability

**URL:** <https://discuss.elastic.co/t/the-remote-web-server-is-affected-by-a-cross-site-scripting-vulnerability/349840>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [December 22, 2023, 6:47am UTC](https://discuss.elastic.co/t/the-remote-web-server-is-affected-by-a-cross-site-scripting-vulnerability/349840 "2023-12-22T06:47:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kesavan](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Post date:** [December 22, 2023, 6:47am UTC](https://discuss.elastic.co/t/the-remote-web-server-is-affected-by-a-cross-site-scripting-vulnerability/349840/1 "2023-12-22T06:47:21Z")

</div>

In Our QA system we are facing the below security scan finding.

Scanning tool used: **nessus**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/6/b60ed403c03a97a6447f0892bff407ef5a8999b2.png)

Above image text:

|Medium|172.16.1.218|tcp|9201|Web Server Generic XSS|The remote web server is affected by a cross-site scripting  
vulnerability.|The remote host is running a web server that fails to adequately  
sanitize request strings of malicious JavaScript. A remote attacker  
can exploit this issue, via a specially crafted request, to execute  
arbitrary HTML and script code in a user's browser within the security  
context of the affected site.|Contact the vendor for a patch or upgrade.|  
| --- | --- | --- | --- | --- |

We are currently using Elasticsearch version 7.17.5 and spring-data-elasticsearch version 4.4.2.

Elastic running as a docker container.

Has anyone else encountered a similar issue? how to resolve this one?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 22, 2023, 11:23am UTC](https://discuss.elastic.co/t/the-remote-web-server-is-affected-by-a-cross-site-scripting-vulnerability/349840/2 "2023-12-22T11:23:25Z")

</div>

Seems like a bug in Nessus, I suggest you ask them for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2024, 11:24am UTC](https://discuss.elastic.co/t/the-remote-web-server-is-affected-by-a-cross-site-scripting-vulnerability/349840/3 "2024-01-19T11:24:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
