Back to Database
Status published
Medium
CVE-2019-8400
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error...
Vulnerability Description
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-8400
Credits & Attribution
No credits recorded in the NVD database.
References
- https://drive.google.com/file/d/1-25expUYVfK6vsiCmEabUCuelOP7aUDj/view?usp=drivesdk
- https://www.youtube.com/watch?v=RIyZLeKEC8E
- https://github.com/ory/hydra/blob/master/CHANGELOG.md#v100-rc3oryos9-2018-12-06
- https://hackerone.com/reports/456333
- https://github.com/ory/hydra/commit/9b5bbd48a72096930af08402c5e07fce7dd770f3
More from ory
View All →CVE-2024-45042
Ory Kratos's `highest_available` setting does not properly respect code + mfa credentials
Medium
4.4
CVE-2021-32701
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
High
7.5
CVE-2020-5300
Disallow replay of `private_key_jwt` by blacklisting JTIs in Hydra
Medium
5.8
CVE-2020-15234
Redirect URL matching ignores character casing
Medium
6.1
CVE-2020-15233
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
Medium
6.1
Affected Vendor
Affected Software
hydra
Vulnerable Versions:
0.1, 0.2.0, 0.3.0, 0.3.1, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.5.8, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.6.7, 0.6.8, 0.6.9, 0.6.10, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.7.8, 0.7.9, 0.7.10, 0.7.11, 0.7.12, 0.7.13, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.6, 0.8.7, 0.9.0, 0.9.1, 0.9.2, 0.9.3, 0.9.4, 0.9.5, 0.9.6, 0.9.7, 0.9.8, 0.9.9, 0.9.10, 0.9.11, 0.9.12, 0.9.13, 0.9.14, 0.9.15, 0.9.16, 0.10.0, 0.10.1, 0.10.2, 0.10.3, 0.10.4, 0.10.5, 0.10.6, 0.10.7, 0.10.8, 0.10.9, 0.10.10, 0.11.0, 0.11.1, 0.11.2, 0.11.3, 0.11.4, 0.11.6, 0.11.7, 0.11.9, 0.11.10, 0.11.12, 0.11.14, 1.0.0
Timeline
Official Publish:
February 17th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.