Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2wx-jj66-2hp7

Опубликовано: 25 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 3.8

Описание

Cross-site Scripting in Wildfly

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.

Пакеты

Наименование

org.wildfly:wildfly-parent

maven
Затронутые версииВерсия исправления

<= 23.0.1.Final

23.0.2.Final

EPSS

Процентиль: 51%
0.00284
Низкий

3.8 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
redhat
почти 5 лет назад

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.

CVSS3: 4.8
nvd
больше 4 лет назад

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.

CVSS3: 4.8
debian
больше 4 лет назад

A flaw was found in Wildfly in versions before 23.0.2.Final while crea ...

EPSS

Процентиль: 51%
0.00284
Низкий

3.8 Low

CVSS3

Дефекты

CWE-79