Vulnerability Details CVE-2017-12677
IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive information about the IdentityServer authorization response.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2017-12677
-
cpe:2.3:a:identityserver:identityserver3:2.4.0
-
cpe:2.3:a:identityserver:identityserver3:2.5.0
-
cpe:2.3:a:identityserver:identityserver3:2.5.1
-
cpe:2.3:a:identityserver:identityserver3:2.5.2
-
cpe:2.3:a:identityserver:identityserver3:2.5.3
-
cpe:2.3:a:identityserver:identityserver3:2.6.0