Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1671 | Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri. |
Github GHSA |
GHSA-3p62-6fjh-3p5h | Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC |
Tue, 12 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-11-12T19:43:42.651Z
Reserved: 2022-12-08T11:04:48.560Z
Link: CVE-2022-4361
Updated: 2024-08-03T01:34:50.133Z
Status : Modified
Published: 2023-07-07T20:15:09.813
Modified: 2024-11-21T07:35:08.000
Link: CVE-2022-4361
OpenCVE Enrichment
No data.
EUVD
Github GHSA