GHSA-rfq3-wpjh-ppvg

Suggest an improvement
Source
https://github.com/advisories/GHSA-rfq3-wpjh-ppvg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-rfq3-wpjh-ppvg/GHSA-rfq3-wpjh-ppvg.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-rfq3-wpjh-ppvg
Aliases
Published
2023-12-22T18:30:30Z
Modified
2024-02-15T05:33:46.534199Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability
Details

WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

Database specific
{
    "nvd_published_at": "2023-12-18T09:15:05Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-12-22T21:31:02Z"
}
References

Affected packages

Maven / org.wso2.carbon.registry:carbon-registry

Package

Name
org.wso2.carbon.registry:carbon-registry
View open source insights on deps.dev
Purl
pkg:maven/org.wso2.carbon.registry/carbon-registry

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.37

Affected versions

4.*

4.6.11
4.6.12
4.6.13
4.6.14
4.6.15
4.6.16
4.6.17
4.6.18
4.6.19
4.6.20
4.6.21
4.6.22
4.6.23
4.6.24
4.6.25
4.6.26
4.6.27
4.6.28
4.6.29
4.6.30
4.6.31
4.6.32
4.6.33
4.6.34
4.6.35
4.6.36
4.6.37
4.6.38
4.6.39
4.6.40
4.6.41
4.6.42
4.7.13
4.7.14
4.7.15
4.7.16
4.7.17
4.7.25
4.7.26
4.7.27
4.7.28
4.7.31
4.7.32
4.7.33
4.7.34
4.7.35
4.7.36