ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
References
Link | Resource |
---|---|
https://drive.google.com/file/d/1-25expUYVfK6vsiCmEabUCuelOP7aUDj/view?usp=drivesdk | Release Notes Third Party Advisory |
https://github.com/ory/hydra/blob/master/CHANGELOG.md#v100-rc3oryos9-2018-12-06 | Release Notes Third Party Advisory |
https://github.com/ory/hydra/commit/9b5bbd48a72096930af08402c5e07fce7dd770f3 | Patch Third Party Advisory |
https://hackerone.com/reports/456333 | Exploit Issue Tracking Third Party Advisory |
https://www.youtube.com/watch?v=RIyZLeKEC8E | Exploit Third Party Advisory |
https://drive.google.com/file/d/1-25expUYVfK6vsiCmEabUCuelOP7aUDj/view?usp=drivesdk | Release Notes Third Party Advisory |
https://github.com/ory/hydra/blob/master/CHANGELOG.md#v100-rc3oryos9-2018-12-06 | Release Notes Third Party Advisory |
https://github.com/ory/hydra/commit/9b5bbd48a72096930af08402c5e07fce7dd770f3 | Patch Third Party Advisory |
https://hackerone.com/reports/456333 | Exploit Issue Tracking Third Party Advisory |
https://www.youtube.com/watch?v=RIyZLeKEC8E | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://drive.google.com/file/d/1-25expUYVfK6vsiCmEabUCuelOP7aUDj/view?usp=drivesdk - Release Notes, Third Party Advisory | |
References | () https://github.com/ory/hydra/blob/master/CHANGELOG.md#v100-rc3oryos9-2018-12-06 - Release Notes, Third Party Advisory | |
References | () https://github.com/ory/hydra/commit/9b5bbd48a72096930af08402c5e07fce7dd770f3 - Patch, Third Party Advisory | |
References | () https://hackerone.com/reports/456333 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://www.youtube.com/watch?v=RIyZLeKEC8E - Exploit, Third Party Advisory |
Information
Published : 2019-02-17 06:29
Updated : 2024-11-21 04:49
NVD link : CVE-2019-8400
Mitre link : CVE-2019-8400
CVE.ORG link : CVE-2019-8400
JSON object : View
Products Affected
ory
- hydra
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')