Reflected cross-site scripting (XSS) In org.keycloak:keycloak-parent
Description
Keycloak vulnerable to cross-site scripting via the state parameter
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using response_mode=form_post it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | - | ||
maven | - | ||
npm | 4.1.0, 4.4.0 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1.