JBoss KeyCloak Cross-site Scripting Vulnerability
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Aug 16, 2023
Package
Affected versions
< 1.1.0.Beta1
Patched versions
1.1.0.Beta1
Description
Published by the National Vulnerability Database
Dec 10, 2019
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Aug 7, 2023
Last updated
Aug 16, 2023
If a JBoss Keycloak application was configured to use
*
as a permitted web origin in the Keycloak administrative console, crafted requests to thelogin-status-iframe.html
endpoint could inject arbitrary Javascript into the generated HTML code via the "origin" query parameter, leading to a cross-site scripting (XSS) vulnerability.References