Skip to content

Reflected XSS on clients-registrations endpoint

Moderate
abstractj published GHSA-m98g-63qj-fp8j Apr 25, 2022

Package

No package listed

Affected versions

< 18.0.0

Patched versions

18.0.0

Description

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. When a malicious request is sent to the client registration endpoint, the error message is not properly escaped, allowing an attacker to execute malicious scripts into the user's browser.

Acknowledgement

Keycloak would like to thank Quentin TEXIER (Pentester at Opencyber) for reporting this issue.

Severity

Moderate

CVE ID

CVE-2021-20323

Weaknesses