CVE-2018-8899
22.03.2018, 05:29
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
Vendor | Product | Version |
---|---|---|
identityserver | identityserver4 | 1.0.0 ≤ 𝑥 ≤ 1.5.2 |
identityserver | identityserver4 | 2.0.0 ≤ 𝑥 ≤ 2.1.2 |
𝑥
= Vulnerable software versions
References