Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12158

Опубликовано: 26 окт. 2017
Источник: debian
EPSS Низкий

Описание

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 61%
0.01021
Низкий

Связанные уязвимости

CVSS3: 5.4
redhat
почти 9 лет назад

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

CVSS3: 5.4
nvd
почти 9 лет назад

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

CVSS3: 5.4
github
больше 4 лет назад

Keycloak Reflected XSS

EPSS

Процентиль: 61%
0.01021
Низкий