/
Security Advisory WSO2-2019-0655
com.atlassian.confluence.content.render.xhtml.migration.exceptions.UnknownMacroMigrationException: The macro 'next_previous_links' is unknown.
Security Advisory WSO2-2019-0655
Published: 02nd December 2019
Severity: Medium
CVSS Score: 5.8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L)
AFFECTED PRODUCTS
WSO2 IS as Key Manager
WSO2 Identity Server
OVERVIEW
WSO2 Carbon Management Console retrieves several external JavaScript libraries via an unencrypted HTTP channel.
DESCRIPTION
Several JavaScript libraries used by the XACML entitlement user interfaces of WSO2 Carbon Management Console are retrieved from external sources over unencrypted HTTP channel.
IMPACT
A malicious entity may intercept the unencrypted HTTP request used to retrieve the JavaScript content and/or alter the unencrypted HTTP response to include malicious content, in combination with other attack vectors such as man-in-the-middle attacks.
SOLUTION
Upgrade the WSO2 IS as Key Manager to 5.9.0 and WSO2 Identity Server to 5.9.0 or higher released version which is not affected by this vulnerability. If you have any questions, post them to security@wso2.com.
Note: If you are a WSO2 customer with Support Subscription, please use WSO2 Update Manager (WUM) updates in order to apply the fix to the affected versions.
, multiple selections available,
Related content
Security Advisory WSO2-2019-0618
Security Advisory WSO2-2019-0618
More like this
Security Advisory WSO2-2019-0624
Security Advisory WSO2-2019-0624
More like this
Security Advisory WSO2-2019-0616
Security Advisory WSO2-2019-0616
More like this
Security Advisory WSO2-2019-0504
Security Advisory WSO2-2019-0504
More like this
Security Advisory WSO2-2020-0685
Security Advisory WSO2-2020-0685
More like this
Security Advisory WSO2-2020-1132
Security Advisory WSO2-2020-1132
More like this
com.atlassian.confluence.content.render.xhtml.migration.exceptions.UnknownMacroMigrationException: The macro 'next_previous_links2' is unknown.