A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
2021-05-20T13:15:07.840
2024-11-21T06:21:47.183
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | build_of_quarkus | - | Yes |
| Application | redhat | data_grid | 8.0 | Yes |
| Application | redhat | descision_manager | 7.0 | Yes |
| Application | redhat | integration_camel_k | - | Yes |
| Application | redhat | integration_camel_quarkus | - | Yes |
| Application | redhat | integration_service_registry | - | Yes |
| Application | redhat | jboss_a-mq | 7 | Yes |
| Application | redhat | jboss_enterprise_application_platform | 7.0 | Yes |
| Application | redhat | wildfly | < 23.0.2 | Yes |