Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
GHSA-755v-r4x4-qf7m · CVE-2022-0225 · GHSA-fqc7-5xxc-ph7r
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
A Stored XSS vulnerability was reported in the Keycloak Security mailing list, affecting all the versions of Keycloak, including the latest release (16.0.1). The vulnerability allows a privileged attacker to execute malicious scripts in the admin console, abusing of the groups' dropdown functionality.
Impact
Successful attacks of this vulnerability can result a privileged attacker to load a XSS script, and steal data from other users. The impact can be considered moderate to low, considering privileged credentials are required.
References
- Please refer to the Keycloak Security mailing list for more information.
Ready to move
Start Securing
Free, no credit card | First findings in minutes