Launch Week Day 1: Announcing Security Design Review
CRITICAL 10.0 Maven

Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC

GHSA-3p62-6fjh-3p5h · CVE-2022-4361

Published · Modified

Description

AssertionConsumerServiceURL is a Java implementation for SAML Service Providers (org.keycloak.protocol.saml). Affected versions of this package are vulnerable to Cross-site Scripting (XSS).

AssertionConsumerServiceURL allows XSS when sending a crafted SAML XML request.

Ready to move

Start Securing

Free, no credit card | First findings in minutes