CVE-2019-3872
published 2019-06-12CVE-2019-3872: It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.70%
48.9th percentile
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | picketlink | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5qcq-825g-ghpg: It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7
ghsa_unreviewed·2022-05-24
CVE-2019-3872 [MEDIUM] CWE-79 GHSA-5qcq-825g-ghpg: It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
Red Hat
picketlink: reflected XSS in SAMLRequest via RelayState parameter
vendor_redhat·2019-06-10·CVSS 5.4
CVE-2019-3872 [MEDIUM] CWE-79 picketlink: reflected XSS in SAMLRequest via RelayState parameter
picketlink: reflected XSS in SAMLRequest via RelayState parameter
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
No detection rules found.
No public exploits indexed.
2019-06-12
Published