Lucene search

K
osvGoogleOSV:GHSA-458H-WV48-FQ75
HistoryMay 13, 2022 - 1:34 a.m.

Keycloak vulnerable to cross-site scripting via the state parameter

2022-05-1301:34:29
Google
osv.dev
11
keycloak
xss
vulnerability
state parameter
authentication
javascript code
attack

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

41.4%

A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using response_mode=form_post it is possible to inject arbitrary Javascript-Code via the ‘state’-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

41.4%