Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m98g-63qj-fp8j

Опубликовано: 28 апр. 2022
Источник: github
Github: Прошло ревью

Описание

Reflected XSS on clients-registrations endpoint

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. When a malicious request is sent to the client registration endpoint, the error message is not properly escaped, allowing an attacker to execute malicious scripts into the user's browser.

Acknowledgement

Keycloak would like to thank Quentin TEXIER (Pentester at Opencyber) for reporting this issue.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

>= 10.0.0, < 18.0.0

18.0.0

Дефекты

CWE-79

Дефекты

CWE-79