GHSA-rfq3-wpjh-ppvg
Dashboard / Vulnerabilities / GHSA-rfq3-wpjh-ppvg
Summary: WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability
Details: WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-6911, https://github.com/wso2/carbon-registry/commit/878fc7e53c90acc85e303d2af73440014a68b246, https://github.com/wso2/carbon-registry, https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225
Affected packages
Package
Name: org.wso2.carbon.registry:carbon-registry
Purl: pkg:maven/org.wso2.carbon.registry/carbon-registry
Affected ranges
Type: ECOSYSTEM
Events:
