Description
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1193 | A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity. |
Github GHSA |
GHSA-v2wx-jj66-2hp7 | Cross-site Scripting in Wildfly |
References
History
No history.
Subscriptions
Redhat
Subscribe
Build Of Quarkus
Subscribe
Data Grid
Subscribe
Descision Manager
Subscribe
Integration Camel K
Subscribe
Integration Camel Quarkus
Subscribe
Integration Service Registry
Subscribe
Jboss A-mq
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Red Hat Single Sign On
Subscribe
Wildfly
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.095Z
Reserved: 2021-05-05T00:00:00.000Z
Link: CVE-2021-3536
No data.
Status : Modified
Published: 2021-05-20T13:15:07.840
Modified: 2024-11-21T06:21:47.183
Link: CVE-2021-3536
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA