Log injection In org.keycloak:keycloak-services

Description

Keycloak vulnerable to log Injection during WebAuthn authentication or registration A flaw was found in keycloak 22.0.5. Errors in browser client during setup/auth with "Security Key login" (WebAuthn) are written into the form, send to Keycloak and logged without escaping allowing log injection.

Acknowledgements: Special thanks toTheresa Henze for reporting this issue and helping us improve our security.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions