PT-2021-13851 · Red Hat · Keycloak
Manh Van Nguyen
+2
·
Published
2021-03-23
·
Updated
2022-10-21
·
CVE-2021-20222
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
keycloak (affected versions not specified)
Description:
A flaw was found in the new account console of keycloak, allowing malicious code to be executed using the referrer URL. The highest threat from this issue is to data confidentiality and integrity as well as system availability.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak