IdentityServer provides an identity and access management framework deployed across .NET environments for authentication and authorization services, with a focused product portfolio centered on IdentityServer4 and IdentityServer3. The durable vulnerability signal reflects input-handling weaknesses in web-facing identity flows, particularly cross-site scripting vulnerabilities that arise in the context of token generation and user-interaction pages; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Identityserver over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12250MEDIUM IdentityServer IdentityServer4 through 2.4 has stored XSS via the httpContext to the host/Extensions/RequestLoggerMiddleware.cs LogForErrorContext method, which can be triggered by | May 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-8899MEDIUM IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurat | Mar 22, 2018 | 6.1 | 20 | NO | NO |
CVE-2017-12677MEDIUM IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive informa | Aug 8, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Identityserver.
Media articles that mention a CVE ID that affects a product developed by Identityserver — matched by CVE ID, not by vendor name.