Open Redirect Affecting org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui package, versions [0, 5.17.26)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.12% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGWSO2CARBONIDENTITYFRAMEWORK-572856
  • published19 Jun 2020
  • disclosed1 Apr 2020
  • creditVijayakumar Muniraj

Introduced: 1 Apr 2020

CVE-2020-14446  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui to version 5.17.26 or higher.

Overview

org.wso2.carbon.identity.framework:org.wso2.carbon.policyeditor.ui is a package that contains the core components and features required by the WSO2 Identity Server product.

Affected versions of this package are vulnerable to Open Redirect. A client-side open redirect arises when an application incorporates user-controllable data into the target of a redirection in an unsafe way in the management console. This payload is allowing to redirect the user to external domains.

CVSS Scores

version 3.1