[MAVEN:GHSA-484Q-784P-8M5H] Cross-site Scripting in keycloak

Severity Moderate
Affected Packages 3
Fixed Packages 3
CVEs 1

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

ID
MAVEN:GHSA-484Q-784P-8M5H
Severity
moderate
URL
https://github.com/advisories/GHSA-484q-784p-8m5h
Published
2022-02-09T00:58:15
(2 years ago)
Modified
2023-02-01T05:05:16
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 12.0.0
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 12.0.0
Affected pkg:maven/org.keycloak/keycloak-server-spi-private org.keycloak keycloak-server-spi-private < 12.0.0
Fixed pkg:maven/org.keycloak/keycloak-server-spi-private org.keycloak keycloak-server-spi-private = 12.0.0
Affected pkg:maven/org.keycloak/keycloak-parent org.keycloak keycloak-parent < 12.0.0
Fixed pkg:maven/org.keycloak/keycloak-parent org.keycloak keycloak-parent = 12.0.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...