Description
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1948001
Related Vulnerabilities
CVE-2016-4433 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-26479 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-parser
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-13929 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2023-28682 Vulnerability in maven package org.jenkins-ci.plugins:perfpublisher