← Back

Gluu

gluu

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Gluu Server
gluu_server
Oxauth
oxauth

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gluu
1Oxauth
Nov 21, 2024
Sep 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
1Gluu
1Gluu Server
Nov 21, 2024
Feb 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.