Security Advisory WSO2-2017-0198
com.atlassian.confluence.content.render.xhtml.migration.exceptions.UnknownMacroMigrationException: The macro 'next_previous_links' is unknown.

Security Advisory WSO2-2017-0198

Published: 4th September 2017

Severity: Medium

CVSS Score: 4.5 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N)

 

AFFECTED PRODUCTS

 

WSO2 Identity Server 5.3.0

 

OVERVIEW

 

A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Workflow Engine Profile.

 

DESCRIPTION

 

In several versions of the WSO2 Workflow Engine Profile, a XSS vulnerability has been discovered which affects all versions above 5.0.7 of the Identity Workflow implementation.

The older versions of WSO2 Identity which are not listed in this advisory are not vulnerable to this attack.

 

 

IMPACT 

 

An attacker aware of the management console origin can include malicious content in a request and trick a user to click the malicious content via email or a neutral web site. This reflects the attack back to the user’s browser and will execute the injected code, which may generate malicious page results th at will mislead the victim or harm otherwise.

 

SOLUTION

 

Apply the following patches based on your product version by following the instructions in the README file. If you have any questions, post them to security@wso2.com.

Please download the relevant patches based on the products you use following the matrix below. Patches can also be downloaded from http://wso2.com/security-patch-releases/.

 

Code

Product

Version

Patch

IS

WSO2 Identity Server

5.3.0

WSO2-CARBON-PATCH-4.4.0-0991

 

NOTES

 

If you are using newer versions of the products than the ones mentioned in the “SOLUTION” section, this vulnerability is fixed. 

 

com.atlassian.confluence.content.render.xhtml.migration.exceptions.UnknownMacroMigrationException: The macro 'next_previous_links2' is unknown.