CVE-2019-3872: XSS
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
Other sources
It was found that a SAMLRequest containing a script could be processed by Picketlink. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3872?
CVE-2019-3872 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2019-3872?
To fix CVE-2019-3872, upgrade to a patched version of Red Hat JBoss Enterprise Application Platform 7.2.x or 7.1.x.
Which versions are affected by CVE-2019-3872?
CVE-2019-3872 affects Red Hat JBoss Enterprise Application Platform versions 7.2.0 and 7.1.x.
What attack vector does CVE-2019-3872 utilize?
CVE-2019-3872 utilizes cross-site scripting through a malicious SAMLRequest.
What could an attacker achieve using CVE-2019-3872?
An attacker leveraging CVE-2019-3872 could obtain unauthorized information and potentially conduct further attacks.