CVE-2019-3873: XSS
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
Other sources
It was found that Picketlink would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3873?
CVE-2019-3873 is classified with a moderate severity level due to the potential for cross-site scripting exploits.
How do I fix CVE-2019-3873?
To fix CVE-2019-3873, update the JBoss Enterprise Application Platform to the latest patched version.
Which versions of JBoss are affected by CVE-2019-3873?
CVE-2019-3873 affects JBoss Enterprise Application Platform version 7.2.0.
What types of attacks can be executed due to CVE-2019-3873?
CVE-2019-3873 can enable cross-site scripting attacks as well as potentially facilitate further attacks.
Is Red Hat Single Sign-On vulnerable to CVE-2019-3873?
Yes, Red Hat Single Sign-On version 7.0 is affected by CVE-2019-3873.