PT-2023-2226 · Keycloak+1 · Keycloak
Patrick Del Bello
·
Publicado
2023-02-27
·
Atualizado
2025-12-04
·
CVE-2022-4137
CVSS v2.0
9.4
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. The flaw requires a user or administrator to interact with a link in order to be vulnerable, which may compromise user details, allowing them to be changed or collected by an attacker.
API Endpoints: 'oob' OAuth endpoint
The vulnerability may allow an attacker to conduct phishing attacks and alter the appearance of web pages.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Improper Encoding or Escaping of Output
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Keycloak