VDB
Sign up
LOW3.8

GHSA-q4xq-445g-g6ch

Keycloak allows cross-site scripting (XSS)

Details

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-core
Introduced in: 0

No fixed version published yet for org.keycloak:keycloak-core (maven). Pin to a known-safe version or switch to an alternative.

References