DirectorySecurity Advisories
Sign In
Security Advisories

CGA-4w2c-v5hw-5v5c

Published

Last updated

https://images.chainguard.dev/security/CGA-4w2c-v5hw-5v5c
Package

keycloak

Latest Update
Not affected
Aliases
  • CVE-2017-12158
  • GHSA-v38p-mqq3-m6v5

Severity

5.4

Medium

CVSS V3

Summary

Keycloak Reflected XSS

Description

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images