GHSA-3p62-6fjh-3p5h
Dashboard / Vulnerabilities / GHSA-3p62-6fjh-3p5h
Summary: Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC
Details: AssertionConsumerServiceURL is a Java implementation for SAML Service Providers (org.keycloak.protocol.saml). Affected versions of this package are vulnerable to Cross-site Scripting (XSS). AssertionConsumerServiceURL allows XSS when sending a crafted SAML XML request.
References: https://github.com/keycloak/keycloak/security/advisories/GHSA-3p62-6fjh-3p5h, https://nvd.nist.gov/vuln/detail/CVE-2022-4361, https://github.com/keycloak/keycloak/commit/a1cfe6e24e5b34792699a00b8b4a8016a5929e3a, https://bugzilla.redhat.com/show_bug.cgi?id=2151618, https://github.com/keycloak/keycloak
Affected packages
Package
Name: org.keycloak:keycloak-services
Purl: pkg:maven/org.keycloak/keycloak-services
Affected ranges
Type: ECOSYSTEM
Events:
