Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10748

Опубликовано: 02 июл. 2020
Источник: redhat
CVSS3: 6.1

Описание

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

A flaw was found in Keycloak's data filter, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat Single Sign-On 7rh-sso7-keycloakAffected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.1FixedRHSA-2020:281302.07.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1836786keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

CVSS3: 6.1
debian
почти 6 лет назад

A flaw was found in Keycloak's data filter, in version 10.0.1, where i ...

CVSS3: 6.1
github
больше 4 лет назад

Cross-site Scripting in Keycloak

6.1 Medium

CVSS3