Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-484q-784p-8m5h

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Cross-site Scripting in keycloak

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

Пакеты

Наименование

org.keycloak:keycloak-server-spi-private

maven
Затронутые версииВерсия исправления

< 12.0.0

12.0.0

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 12.0.0

12.0.0

EPSS

Процентиль: 50%
0.00271
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4
redhat
больше 5 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

CVSS3: 4.8
nvd
около 5 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

CVSS3: 4.8
debian
около 5 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possib ...

EPSS

Процентиль: 50%
0.00271
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79