Security Advisory

CVE-2017-12677

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-08-08 01:00:00
Last updated 2024-09-16 23:15:23
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive information about the IdentityServer authorization response.