Keycloak allows cross-site scripting (XSS)
Low severity
GitHub Reviewed
Published
Feb 18, 2025
to the GitHub Advisory Database
•
Updated Feb 20, 2025
Description
Published by the National Vulnerability Database
Feb 18, 2025
Published to the GitHub Advisory Database
Feb 18, 2025
Reviewed
Feb 20, 2025
Last updated
Feb 20, 2025
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
References