Cross-Site Scripting Vulnerability in JBoss Application Platform by Red Hat
CVE-2019-3872

5.4MEDIUM

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
12 June 2019

Summary

A security flaw exists in the Picketlink components of JBoss Application Platform versions 7.2.x and 7.1.x. This vulnerability arises from the improper handling of SAMLRequests containing scripts. An attacker may exploit this flaw by injecting malicious scripts, potentially allowing unauthorized access to sensitive information or enabling further attacks against the application. It is crucial for users of these JBoss versions to take immediate action to mitigate the associated risks.

Affected Version(s)

picketlink as shipped with Jboss Enterprise Application Platform 7.2.x and 7.1.x

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.