LOW3.8
GHSA-q4xq-445g-g6ch
Keycloak allows cross-site scripting (XSS)
Details
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-core
Introduced in:
0No fixed version published yet for org.keycloak:keycloak-core (maven). Pin to a known-safe version or switch to an alternative.