QID 981568
QID 981568: Java (maven) Security Update for org.mitre:openid-connect-server (GHSA-c2h6-7gm8-cv4w)
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c2h6-7gm8-cv4w for updates pertaining to this vulnerability.
Vendor References
- GHSA-c2h6-7gm8-cv4w -
github.com/advisories/GHSA-c2h6-7gm8-cv4w
CVEs related to QID 981568
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c2h6-7gm8-cv4w | org.mitre:openid-connect-server |
|