Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10776

Опубликовано: 17 нояб. 2020
Источник: debian
EPSS Низкий

Описание

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 52%
0.00769
Низкий

Связанные уязвимости

CVSS3: 4
redhat
почти 6 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

CVSS3: 4.8
nvd
почти 6 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

CVSS3: 4.8
github
больше 4 лет назад

Cross-site Scripting in keycloak

EPSS

Процентиль: 52%
0.00769
Низкий