A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-6552 A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
Github GHSA Github GHSA GHSA-fqc7-5xxc-ph7r Keycloak XSS via use of malicious payload as group name when creating new group from admin console
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-02T23:18:42.951Z

Reserved: 2022-01-13T00:00:00

Link: CVE-2022-0225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-26T18:15:08.893

Modified: 2024-11-21T06:38:10.943

Link: CVE-2022-0225

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-01-13T00:00:00Z

Links: CVE-2022-0225 - Bugzilla

cve-icon OpenCVE Enrichment

No data.