Server side cross-site scripting In org.keycloak:keycloak-core

Description

Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS)

Duplicate Advisory

This advisory is a duplicate of GHSA-w9mf-83w3-fv49. This link is maintained to preserve external references.

Original Description

A stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version