Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2256
HistorySep 01, 2022 - 9:15 p.m.

Cross site scripting

2022-09-0121:15:00
PRIOn knowledge base
www.prio-n.com
8
cross-site scripting
vulnerability
keycloak
red hat single sign-on
admin console
default roles functionality

5.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

22.7%

A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.

CPENameOperatorVersion
single_sign-oneq7.0

5.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

22.7%