CVE-2017-12158: XSS
Published Sep 6, 2017
·Updated
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.
Affected Software
8 affected componentsFixes available
maven/org.keycloak:keycloak-parent<3.4.0
3.4.0
redhat/Keycloak<3.3.0.
3.3.0.
redhat/Keycloak<3.4.0.
3.4.0.
redhat Single Sign On=7.0
redhat Single Sign On=7.1
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
Keycloak Keycloak
Event History
Oct 26, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
May 13, 2022
Advisory Published
01:38 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-12158?
CVE-2017-12158 has been classified as a high severity vulnerability due to its potential for reflected XSS attacks.
2
How do I fix CVE-2017-12158?
To fix CVE-2017-12158, upgrade Keycloak to version 3.4.0 or later.
3
Which versions of Keycloak are affected by CVE-2017-12158?
Versions of Keycloak prior to 3.4.0 are affected by CVE-2017-12158.
4
Can CVE-2017-12158 be exploited without authentication?
No, CVE-2017-12158 requires the attacker to target an authenticated user.
5
What type of attack is associated with CVE-2017-12158?
CVE-2017-12158 is associated with reflected cross-site scripting (XSS) attacks.