GHSA-m98g-63qj-fp8j
Dashboard / Vulnerabilities / GHSA-m98g-63qj-fp8j
GHSA-m98g-63qj-fp8j
Published: 28 Apr 2022Last Modified: 28 Nov 2024
Summary: Reflected XSS on clients-registrations endpoint
Details: A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. When a malicious request is sent to the client registration endpoint, the error message is not properly escaped, allowing an attacker to execute malicious scripts into the user's browser. ### Acknowledgement Keycloak would like to thank Quentin TEXIER (Pentester at Opencyber) for reporting this issue.
References: https://github.com/keycloak/keycloak/security/advisories/GHSA-m98g-63qj-fp8j, https://github.com/keycloak/keycloak
Affected packages
Package
Name: org.keycloak:keycloak-parent
Purl: pkg:maven/org.keycloak/keycloak-parent
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 10.0.0
Fixed -18.0.0
Affected versions
10.0.0
10.0.1
10.0.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
