A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1948001 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-20T12:15:09

Updated: 2021-05-20T12:15:09

Reserved: 2021-05-05T00:00:00


Link: CVE-2021-3536

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-20T13:15:07.840

Modified: 2021-05-26T15:02:54.977


Link: CVE-2021-3536

JSON object: View

cve-icon Redhat Information

No data.

CWE