XSS in Keycloak
Moderate severity
GitHub Reviewed
Published
Apr 15, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Feb 10, 2020
Reviewed
Apr 15, 2020
Published to the GitHub Advisory Database
Apr 15, 2020
Last updated
Feb 1, 2023
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
References