Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vf3-4w62-m3pq

Опубликовано: 15 апр. 2020
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

XSS in Keycloak

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 9.0.0

9.0.0

EPSS

Процентиль: 51%
0.00283
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
около 6 лет назад

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

CVSS3: 6.1
nvd
почти 6 лет назад

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

CVSS3: 6.1
debian
почти 6 лет назад

It was found in all keycloak versions before 9.0.0 that links to exter ...

EPSS

Процентиль: 51%
0.00283
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79