4.10.31
7 years ago
9 days ago
Known vulnerabilities in the org.wso2.carbon:org.wso2.carbon.ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.wso2.carbon:org.wso2.carbon.ui is a package that provides the Carbon UI Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper output encoding, which can be exploited by tampering the parameter in the Management Console. Note: This vulnerability affects the following products:
How to fix Cross-site Scripting (XSS)? Upgrade | [,4.6.3-m6) |
org.wso2.carbon:org.wso2.carbon.ui is a package that provides the Carbon UI Affected versions of this package are vulnerable to Arbitrary File Upload due to improper validation of user input, a malicious actor could upload an arbitrary file to a user-controlled location of the server. By leveraging the arbitrary file upload vulnerability, it is further possible to gain remote code execution on the server. Note: The vulnerable components are:
How to fix Arbitrary File Upload? Upgrade | [,4.7.0-m9) |
org.wso2.carbon:org.wso2.carbon.ui is a package that provides the Carbon UI Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF). A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. How to fix Server-side Request Forgery (SSRF)? Upgrade | [,4.6.1-m4) |
org.wso2.carbon:org.wso2.carbon.ui is a package that provides the Carbon UI Affected versions of this package are vulnerable to Improper Authentication. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. How to fix Improper Authentication? Upgrade | [,4.6.1-m4) |
org.wso2.carbon:org.wso2.carbon.ui is a package that provides the Carbon UI Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The Try It tool allows Reflected XSS. How to fix Cross-site Scripting (XSS)? Upgrade | [,4.5.1) |
org.wso2.carbon:org.wso2.carbon.ui is a package that provides the Carbon UI Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The Try It tool allows Reflected XSS. How to fix Cross-site Scripting (XSS)? Upgrade | [,4.6.1-m4) |