Description
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
Remediation
References
https://github.com/ant-design/ant-design-pro/pull/5461
Related Vulnerabilities
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2021-21363 Vulnerability in maven package io.swagger:swagger-generator
CVE-2023-25570 Vulnerability in maven package com.ctrip.framework.apollo:apollo
CVE-2022-25894 Vulnerability in maven package com.bstek.uflo:uflo-core