VulnerabilityModified
CVE-2020-5497
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized.
MEDIUM 6.1EPSS 2.13%
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mitreid/connect
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/156574/MITREid-1.3.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Feb/25Mailing List, Third Party Advisory
- https://github.com/mitreid-connect/OpenID-Connect-Java-Spring-Server/issues/1521Exploit, Issue Tracking, Third Party Advisory
- https://www.securitymetrics.com/blog/MITREid-Connect-cross-site-scripting-CVE-2020-5497Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/156574/MITREid-1.3.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Feb/25Mailing List, Third Party Advisory
- https://github.com/mitreid-connect/OpenID-Connect-Java-Spring-Server/issues/1521Exploit, Issue Tracking, Third Party Advisory
- https://www.securitymetrics.com/blog/MITREid-Connect-cross-site-scripting-CVE-2020-5497Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.