Skip to content
Noroxi

identityserver records

3 published records for vendor identityserver.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 18
  3. 19

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

3 records
  • CVE-2018-8899
    24Monitor

    IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, wh

    MediumCVSS 6.1No exploitEPSS 1%

    identityserver · identityserver4Mar 22, 2018

  • IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remo

    MediumCVSS 6.1No exploitEPSS 1%

    identityserver · identityserver3Aug 7, 2017

  • IdentityServer IdentityServer4 through 2.4 has stored XSS via the httpContext to the host/Extensions/RequestLoggerMiddleware.cs LogForErrorC

    MediumCVSS 6.1No exploitEPSS 1%

    identityserver · identityserver4May 21, 2019