VDB
Sign up
MEDIUM6.0

GHSA-8rmm-gm28-pj8q

Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow

Quick fix

GHSA-8rmm-gm28-pj8q — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>22.0.10</version> for org.keycloak:keycloak-services

Details

Keycloak allows arbitrary URLs as SAML Assertion Consumer Service POST Binding URL (ACS), including JavaScript URIs (javascript:).

Allowing JavaScript URIs in combination with HTML forms leads to JavaScript evaluation in the context of the embedding origin on form submission.

#### Acknowledgements: Special thanks to Lauritz Holtmann for reporting this issue and helping us improve our project.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 22.0.10
Fix# pom.xml: bump <version>22.0.10</version> for org.keycloak:keycloak-services
Maven/org.keycloak:keycloak-services
Introduced in: 23.0.0Fixed in: 24.0.3
Fix# pom.xml: bump <version>24.0.3</version> for org.keycloak:keycloak-services

References