CVE-2022-1274

CVSS v3.1 5.4 (Medium)
54% Progress
EPSS 0.08 % (35th)
0.08% Progress
Affected Products 8
Advisories 1

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2023-03-29 21:15:07
(17 months ago)
Updated Date
2023-12-22 16:15:07
(8 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Keycloak prior 20.0.5 version cpe:2.3:a:redhat:keycloak < 20.0.5
  Redhat Single Sign-on cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only

Configuration #2

AND
    CPE23 From Up To
OR  
  Redhat Single Sign-on from 7.6 version and prior 7.6.2 version cpe:2.3:a:redhat:single_sign-on >= 7.6 < 7.6.2
OR  
  Running on/with
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0
OR  
  Running on/with
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
OR  
  Running on/with
  Redhat Enterprise Linux 9.0 cpe:2.3:o:redhat:enterprise_linux:9.0

Configuration #3

AND
    CPE23 From Up To
OR  
  Redhat Openshift Container Platform 4.9 cpe:2.3:a:redhat:openshift_container_platform:4.9
OR  
  Running on/with
  Redhat Openshift Container Platform 4.10 cpe:2.3:a:redhat:openshift_container_platform:4.10
OR  
  Running on/with
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
OR  
  Running on/with
  Redhat Enterprise Linux for Ibm Z Systems 8.0 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0
OR  
  Running on/with
  Redhat Enterprise Linux for Ibm Z Systems Eus 8.0 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.0
OR  
  Running on/with
  Redhat Enterprise Linux for Power Little Endian 8.0 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0
OR  
  Running on/with
  Redhat Enterprise Linux for Power Little Endian Eus 8.0 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...