org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui@5.16.83 vulnerabilities

  • latest version

    7.6.7

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Open Redirect

    org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui is a package that contains the core components and features required by the WSO2 Identity Server product.

    Affected versions of this package are vulnerable to Open Redirect. A client-side open redirect arises when an application incorporates user-controllable data into the target of a redirection in an unsafe way in the management console. This payload is allowing to redirect the user to external domains.

    How to fix Open Redirect?

    Upgrade org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui to version 5.17.26 or higher.

    [0,5.17.26)
    • M
    Cross-site Scripting (XSS)

    org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui is a package that contains the core components and features required by the WSO2 Identity Server product.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). More specifically, it is a potential Reflected Cross-Site Scripting vulnerability in the Management Console Basic Policy Editor user Interface.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui to version 5.16.118 or higher.

    [0,5.16.118)