Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 Maven

Keycloak Reflected XSS

GHSA-v38p-mqq3-m6v5 · CVE-2017-12158

Published · Modified

Description

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes