VDB
Sign up
MEDIUM5.4

GHSA-v38p-mqq3-m6v5

Keycloak Reflected XSS

Quick fix

GHSA-v38p-mqq3-m6v5 — org.keycloak:keycloak-parent: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.4.0</version> for org.keycloak:keycloak-parent

Details

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-parent
Introduced in: 0Fixed in: 3.4.0
Fix# pom.xml: bump <version>3.4.0</version> for org.keycloak:keycloak-parent

References