IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive information about the IdentityServer authorization response.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2017-08-08T01:00:00Z
Updated: 2024-09-16T23:15:23.174Z
Reserved: 2017-08-07T00:00:00Z
Link: CVE-2017-12677

No data.

Status : Modified
Published: 2017-08-08T01:34:00.033
Modified: 2024-11-21T03:10:01.523
Link: CVE-2017-12677

No data.