CVE-2020-10776: XSS
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirecturi parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Other sources
A flaw was found in Keycloak, where it is possible to add unsafe schemes for the redirecturi parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
OIDC redirecturi allows dangerous schemes resulting in potential XSS
https://issues.redhat.com/browse/KEYCLOAK-14306
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-10776?
CVE-2020-10776 is a vulnerability found in Keycloak before version 12.0.0 that allows an attacker to perform a Cross-site scripting attack.
What is the severity of CVE-2020-10776?
CVE-2020-10776 has a severity level of medium (4) based on the CVSS score.
How can an attacker exploit CVE-2020-10776?
An attacker can exploit CVE-2020-10776 by adding unsafe schemes for the redirect_uri parameter, enabling them to perform a Cross-site scripting attack.
What is the affected software for CVE-2020-10776?
Keycloak before version 12.0.0 is affected by CVE-2020-10776.
How can I fix CVE-2020-10776?
To fix CVE-2020-10776, upgrade to Keycloak version 12.0.0 or higher.