Описание
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
Отчет
Red Hat rates this as a Low impact since this requires previous high privileged administrator account to perform this operation.
Меры по смягчению последствий
Currently the is no mitigation available for this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Keycloak | keycloak-core | Not affected | ||
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.8 Low
CVSS3
Связанные уязвимости
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
A vulnerability was found in Keycloak. This issue may allow a privileg ...
3.8 Low
CVSS3