[MAVEN:GHSA-3P62-6FJH-3P5H] Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

AssertionConsumerServiceURL is a Java implementation for SAML Service Providers (org.keycloak.protocol.saml). Affected versions of this package are vulnerable to Cross-site Scripting (XSS).

AssertionConsumerServiceURL allows XSS when sending a crafted SAML XML request.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services < 21.1.2
Package Fixed Version
pkg:maven/org.keycloak/keycloak-services = 21.1.2
ID
MAVEN:GHSA-3P62-6FJH-3P5H
Severity
critical
URL
https://github.com/advisories/GHSA-3p62-6fjh-3p5h
Published
2023-06-30T20:30:50
(14 months ago)
Modified
2023-11-06T05:05:08
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 21.1.2
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 21.1.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...