A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Redhat
Subscribe
|
Build Of Quarkus
Subscribe
Data Grid
Subscribe
Descision Manager
Subscribe
Integration Camel K
Subscribe
Integration Camel Quarkus
Subscribe
Integration Service Registry
Subscribe
Jboss A-mq
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Red Hat Single Sign On
Subscribe
Wildfly
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1193 | A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity. |
Github GHSA |
GHSA-v2wx-jj66-2hp7 | Cross-site Scripting in Wildfly |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.095Z
Reserved: 2021-05-05T00:00:00
Link: CVE-2021-3536
No data.
Status : Modified
Published: 2021-05-20T13:15:07.840
Modified: 2024-11-21T06:21:47.183
Link: CVE-2021-3536
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA