Cross-Site Scripting Vulnerability in JBoss Application Platform by Red Hat
CVE-2019-3872
5.4MEDIUM
What is CVE-2019-3872?
A security flaw exists in the Picketlink components of JBoss Application Platform versions 7.2.x and 7.1.x. This vulnerability arises from the improper handling of SAMLRequests containing scripts. An attacker may exploit this flaw by injecting malicious scripts, potentially allowing unauthorized access to sensitive information or enabling further attacks against the application. It is crucial for users of these JBoss versions to take immediate action to mitigate the associated risks.
Affected Version(s)
picketlink as shipped with Jboss Enterprise Application Platform 7.2.x and 7.1.x