Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5968-qw33-h47j

Опубликовано: 15 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.6

Описание

Duplicate Advisory: Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-cvg2-7c3j-g36j. This link is maintained to preserve external references.

Original Description

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 23.0.3

23.0.3

4.6 Medium

CVSS3

Дефекты

CWE-75

4.6 Medium

CVSS3

Дефекты

CWE-75