OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`
Low severity
GitHub Reviewed
Published
Jun 22, 2026
in
OpenIdentityPlatform/OpenAM
•
Updated Jun 22, 2026
Package
Affected versions
< 16.1.1
Patched versions
16.1.1
Description
Published to the GitHub Advisory Database
Jun 22, 2026
Reviewed
Jun 22, 2026
Last updated
Jun 22, 2026
Summary
Certain federation endpoints do not consistently apply output encoding when rendering user-supplied parameters into HTML responses. Under a non-default configuration used in some clustered deployments, this inconsistency can result in reflected XSS in the OpenAM origin without authentication.
References