Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v38p-mqq3-m6v5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Keycloak Reflected XSS

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 3.4.0

3.4.0

EPSS

Процентиль: 71%
0.00668
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 8 лет назад

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

CVSS3: 5.4
nvd
больше 8 лет назад

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

CVSS3: 5.4
debian
больше 8 лет назад

It was found that Keycloak would accept a HOST header URL in the admin ...

EPSS

Процентиль: 71%
0.00668
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79