/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-4028

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-4028

CGA ID

CGA-hf7q-rhr4-549m

Severity

3.8

Low

CVSS V3

Summary

Keycloak allows cross-site scripting (XSS)

Description

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.

References

  • https://images.chainguard.dev/security/CGA-hf7q-rhr4-549m

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images