PT-2022-13045 · Red Hat · Keycloak

Jxn0

·

Published

2022-08-26

·

Updated

2022-11-29

·

CVE-2022-0225

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 16.0.1
Description A flaw was found in Keycloak, allowing a privileged attacker to use a malicious payload as the group name while creating a new group from the admin console. This leads to a stored Cross-site scripting (XSS) attack, enabling the execution of malicious scripts in the admin console by abusing the groups' dropdown functionality. Successful attacks can result in a privileged attacker loading a XSS script and stealing data from other users.
Recommendations For Keycloak versions prior to 16.0.1, consider disabling the group creation functionality in the admin console as a temporary workaround until a patch is available. Restrict access to the admin console to minimize the risk of exploitation. Avoid using the group name field in the admin console until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-0225
GHSA-755V-R4X4-QF7M
GHSA-FQC7-5XXC-PH7R
RHSA-2022:6782
RHSA-2022:6783
RHSA-2022:7409
RHSA-2022:7410
RHSA-2022:7411

Affected Products

Keycloak