ZeroHour

CVE-2021-3536

CVSS 3.1
4.8 medium
EPSS
<1%p43
Published
()
Modified
Description

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.

Vendors
redhat
Products
build of quarkus, data grid, descision manager, integration camel k, integration camel quarkus, integration service registry, jboss a-mq, jboss enterprise application platform, wildfly
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.