-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.wso2.am:am-parent | maven | >= 4.2.0-beta, <= 4.2.0 | |
| org.wso2.am:am-parent | maven | >= 4.1.0-alpha, <= 4.1.0 | |
| org.wso2.am:am-parent | maven | >= 4.0.0-beta, <= 4.0.0 | |
| org.wso2.is:identity-server-parent | maven | >= 6.1.0-beta, <= 6.1.0 | |
| org.wso2.is:identity-server-parent | maven | >= 6.0.0-alpha3, <= 6.0.0 | |
| org.wso2.is:identity-server-parent | maven | >= 5.11.0-alpha, <= 5.11.0 |
The vulnerability stems from improper token type validation and session management. Based on WSO2 architecture patterns:
Ongoing coverage of React2Shell