PT-2023-5051 · Red Hat · Keycloak

Mulliken

·

Published

2023-02-27

·

Updated

2023-09-25

·

CVE-2022-1438

CVSS v2.0

6.8

Medium

VectorAV:N/AC:H/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak, where under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability. This issue can be exploited by an attacker to conduct a Cross-site scripting attack. The vulnerability is related to insufficient protection measures for the web page structure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-05596
CVE-2022-1438
GHSA-W354-2F3C-QVG9
RHSA-2023:1043
RHSA-2023:1044
RHSA-2023:1045

Affected Products

Keycloak