[MAVEN:GHSA-J628-Q885-8GR5] Keycloak vulnerable to log Injection during WebAuthn authentication or registration

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

A flaw was found in keycloak 22.0.5. Errors in browser client during setup/auth with "Security Key login" (WebAuthn) are written into the form, send to Keycloak and logged without escaping allowing log injection.

Acknowledgements:
Special thanks toTheresa Henze for reporting this issue and helping us improve our security.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services >= 23.0.0, < 23.0.5
pkg:maven/org.keycloak/keycloak-services < 22.0.9
ID
MAVEN:GHSA-J628-Q885-8GR5
Severity
low
URL
https://github.com/advisories/GHSA-j628-q885-8gr5
Published
2024-04-17T18:24:03
(5 months ago)
Modified
2024-04-17T18:24:04
(5 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services >= 23.0.0 < 23.0.5
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 23.0.5
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 22.0.9
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 22.0.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...