Skip to content

Stored XSS in groups dropdown

Moderate
abstractj published GHSA-755v-r4x4-qf7m Nov 24, 2022

Package

No package listed

Affected versions

< 20.0.0

Patched versions

20.0.0

Description

Summary

A Stored XSS vulnerability was reported in the Keycloak Security mailing list, affecting all the versions of Keycloak, including the latest release (16.0.1). The vulnerability allows a privileged attacker to execute malicious scripts in the admin console, abusing of the groups' dropdown functionality.

Impact

Successful attacks of this vulnerability can result a privileged attacker to load a XSS script, and steal data from other users. The impact can be considered moderate to low, considering privileged credentials are required.

References

  • Please refer to the Keycloak Security mailing list for more information.

Severity

Moderate

CVE ID

CVE-2022-0225

Weaknesses

Credits