CVE-2020-10748: XSS
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
Other sources
A flaw was found in Keycloak's data filter, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
Insufficient filtering of Client baseUrl (follow-up to CVE-2020-1697)
https://issues.redhat.com/browse/KEYCLOAK-14149
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2020-10748.
What is the severity of CVE-2020-10748?
The severity of CVE-2020-10748 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2020-10748?
The affected software for CVE-2020-10748 includes Keycloak version 10.0.1 and Redhat Single Sign-on up to version 7.4.1.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to conduct cross-site scripting or further attacks.
How can I fix CVE-2020-10748?
To fix CVE-2020-10748, update Keycloak to version 7.4.1 or above.