GluuCVEs & Vulnerabilities
2 CVEs affecting Gluu products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
gluu server 1oxauth 1
CVE-2022-36663CRITICAL
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
7 Sep 2022
9.8
CVSS
CVE-2020-9012MEDIUM
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.
16 Feb 2020
6.1
CVSS
← PrevPage 1 / 1Next →