Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-755v-r4x4-qf7m

Опубликовано: 29 нояб. 2022
Источник: github
Github: Прошло ревью

Описание

Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown

Summary

A Stored XSS vulnerability was reported in the Keycloak Security mailing list, affecting all the versions of Keycloak, including the latest release (16.0.1). The vulnerability allows a privileged attacker to execute malicious scripts in the admin console, abusing of the groups' dropdown functionality.

Impact

Successful attacks of this vulnerability can result a privileged attacker to load a XSS script, and steal data from other users. The impact can be considered moderate to low, considering privileged credentials are required.

References

  • Please refer to the Keycloak Security mailing list for more information.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 20.0.0

20.0.0

Дефекты

CWE-80

Дефекты

CWE-80