Описание
A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Applications 6 | mta/mta-ui-rhel9 | Will not fix | ||
| Migration Toolkit for Applications 7 | mta/mta-ui-rhel9 | Not affected | ||
| Red Hat build of Apicurio Registry 2 | keycloak | Affected | ||
| Red Hat build of Quarkus | org.keycloak/keycloak-core | Not affected | ||
| Red Hat Data Grid 8 | keycloak | Will not fix | ||
| Red Hat Decision Manager 7 | keycloak | Fix deferred | ||
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | ||
| Red Hat Fuse 7 | keycloak | Will not fix | ||
| Red Hat JBoss Data Grid 7 | keycloak | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 6 | keycloak | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
6 Medium
CVSS3
Связанные уязвимости
A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.
A flaw was found in the SAML client registration in Keycloak that coul ...
Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow
Уязвимость модуля единого входа в приложения (SAML) программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
EPSS
6 Medium
CVSS3