CVE-2021-20323: XSS
Published Oct 13, 2021
·Updated
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
Other sources
A POST based reflected Cross Site Scripting vulnerability on Keycloak version 15.
— Red Hat
Affected Software
2 affected componentsFixes available
redhat/keycloak<18.0.0
18.0.0
redhat Keycloak<17.0.0
Event History
Oct 13, 2021
Data Sourced
via Red Hat·09:50 AM
DescriptionSeverityAffected Software
Mar 25, 2022
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20323?
CVE-2021-20323 is a POST based reflected Cross Site Scripting vulnerability in Keycloak.
2
How severe is CVE-2021-20323?
CVE-2021-20323 has a severity rating of medium (6.1).
3
Which software is affected by CVE-2021-20323?
The affected software includes Redhat Keycloak versions up to 17.0.0 and redhat/keycloak versions up to 18.0.0.
4
How can I fix CVE-2021-20323?
To fix CVE-2021-20323, update your Keycloak installation to version 18.0.0 or higher.
5
Where can I find more information about CVE-2021-20323?
More information about CVE-2021-20323 can be found at the following link: https://bugzilla.redhat.com/show_bug.cgi?id=2013577