Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10776

Опубликовано: 04 нояб. 2020
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

A flaw was found in Keycloak, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

Меры по смягчению последствий

Trusted Hosts Policy could be used to mitigate this attack : https://www.keycloak.org/docs/latest/securing_apps/index.html#client-registration-policies

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.3FixedRHSA-2020:493104.11.2020
Red Hat Single Sign-On 7.4 for RHEL 6rh-sso7-keycloakFixedRHSA-2020:492904.11.2020
Red Hat Single Sign-On 7.4 for RHEL 7rh-sso7-keycloakFixedRHSA-2020:493004.11.2020
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-keycloakFixedRHSA-2020:493204.11.2020
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-libunix-dbus-javaFixedRHSA-2020:493204.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1847428keycloak: OIDC redirect_uri allows dangerous schemes resulting in potential XSS

EPSS

Процентиль: 50%
0.00271
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
около 5 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

CVSS3: 4.8
debian
около 5 лет назад

A flaw was found in Keycloak before version 12.0.0, where it is possib ...

CVSS3: 4.8
github
почти 4 года назад

Cross-site Scripting in keycloak

EPSS

Процентиль: 50%
0.00271
Низкий

4 Medium

CVSS3