Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10748

Опубликовано: 02 июл. 2020
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

A flaw was found in Keycloak's data filter, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat Single Sign-On 7rh-sso7-keycloakAffected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.1FixedRHSA-2020:281302.07.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1836786keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)

EPSS

Процентиль: 50%
0.00271
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

CVSS3: 6.1
debian
больше 5 лет назад

A flaw was found in Keycloak's data filter, in version 10.0.1, where i ...

CVSS3: 6.1
github
почти 4 года назад

Cross-site Scripting in Keycloak

EPSS

Процентиль: 50%
0.00271
Низкий

6.1 Medium

CVSS3