7.6.7
8 years ago
2 months ago
Known vulnerabilities in the org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui is a package that contains the core components and features required by the WSO2 Identity Server product. Affected versions of this package are vulnerable to Open Redirect. A client-side open redirect arises when an application incorporates user-controllable data into the target of a redirection in an unsafe way in the management console. This payload is allowing to redirect the user to external domains. How to fix Open Redirect? Upgrade | [0,5.17.26) |
org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui is a package that contains the core components and features required by the WSO2 Identity Server product. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). More specifically, it is a potential Reflected Cross-Site Scripting vulnerability in the Management Console Basic Policy Editor user Interface. How to fix Cross-site Scripting (XSS)? Upgrade | [0,5.16.118) |
org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui is a package that contains the core components and features required by the WSO2 Identity Server product. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It is a Reflected Cross-Site Scripting vulnerability located in the Management Console Policy Administration user interface. How to fix Cross-site Scripting (XSS)? Upgrade | [0,5.16.72) |