SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5497

The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized.

MEDIUM 6.1EPSS 2.13%

Does this matter?

Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.

Description

The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mitreid/connect
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.