org.wso2.carbon.identity.framework:org.wso2.carbon.identity.entitlement.ui@5.11.83 vulnerabilities

  • latest version

    7.6.7

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    10 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.wso2.carbon.identity.framework:org.wso2.carbon.identity.entitlement.ui package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Open Redirect

    org.wso2.carbon.identity.framework:org.wso2.carbon.identity.entitlement.ui is a Carbon bundle that represent the Entitlement Aggregator module.

    Affected versions of this package are vulnerable to Open Redirect. A client-side open redirect arises when an application incorporates user-controllable data into the target of a redirection in an unsafe way in the management console. This payload is allowing to redirect the user to external domains.

    How to fix Open Redirect?

    Upgrade org.wso2.carbon.identity.framework:org.wso2.carbon.identity.entitlement.ui to version 5.17.26 or higher.

    [0,5.17.26)