CVE-2019-3873
12.06.2019, 14:29
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
Vendor | Product | Version |
---|---|---|
redhat | jboss_enterprise_application_platform | 7.2.0 |
redhat | single_sign-on | 7.0 |
𝑥
= Vulnerable software versions