laptop and a wrench

Bug

There is a reflected cross-site scripting (XSS) vulnerability in Portal for ArcGIS.

Last Published: October 21, 2021 Portal for ArcGIS
Bug ID Number BUG-000137733
SubmittedFebruary 25, 2021
Last ModifiedApril 1, 2024
Applies toPortal for ArcGIS
Version found10.8.1
Operating SystemWindows OS
Operating System Version2019 64 Bit
Version Fixed10.9
StatusFixed

Workaround

The Portal for ArcGIS Security 2022 Update 1 Patch is now live on the support site. The URL is: https://support.esri.com/en/download/7948. This is a 3 version patch for 10.7.1, 10.8.1 and 10.9.1. Refer to the Issues Addressed section of the patch download page for details on which versions were affected and resolved for this defect.

Steps to Reproduce

Bug ID: BUG-000137733

Software:

  • Portal for ArcGIS

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options

Discover more on this topic