Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1697

Опубликовано: 05 фев. 2020
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

A flaw was found during the assessment of the Admin Console application for Keycloak, where it was found that Application Links to external applications are not validated properly. An attacker could use this flaw to cause Stored XSS attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakNot affected
Red Hat Mobile Application Platform 4keycloakOut of support scope
Red Hat OpenShift Application RuntimeskeycloakAffected
Red Hat Single Sign-On 7rh-sso7-keycloakAffected
Red Hat support for Spring BootkeycloakAffected
Red Hat Runtimes Spring Boot 2.2.6keycloakFixedRHSA-2020:225201.06.2020
Red Hat Single Sign-On 7.3FixedRHSA-2020:044506.02.2020
Text-Only RHOARFixedRHSA-2020:290523.07.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1791538keycloak: stored XSS in client settings via application links

EPSS

Процентиль: 51%
0.00283
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

CVSS3: 6.1
debian
почти 6 лет назад

It was found in all keycloak versions before 9.0.0 that links to exter ...

CVSS3: 5.4
github
почти 6 лет назад

XSS in Keycloak

EPSS

Процентиль: 51%
0.00283
Низкий

6.1 Medium

CVSS3