CVE-2022-1274: XSS
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
Other sources
The execute-actions-email endpoint of the Keycloak Admin REST API allows a malicious actor to send emails containing phishing links to Keycloak users.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-1274?
CVE-2022-1274 is a vulnerability found in Keycloak that allows arbitrary HTML to be injected into emails sent to Keycloak users, potentially leading to phishing or other attacks.
What is the severity of CVE-2022-1274?
The severity of CVE-2022-1274 is high, with a severity value of 7.6.
Which software versions are affected by CVE-2022-1274?
Versions 0:18.0.6-1.redhat_00001.1.el7, 0:18.0.6-1.redhat_00001.1.el8, and 0:18.0.6-1.redhat_00001.1.el9 of rh-sso7-keycloak are affected by CVE-2022-1274.
How can the CVE-2022-1274 vulnerability be exploited?
The CVE-2022-1274 vulnerability can be exploited by injecting arbitrary HTML into emails sent to Keycloak users, allowing for phishing or other attacks.
Where can I find more information about CVE-2022-1274?
You can find more information about CVE-2022-1274 on the Red Hat website at the following links: [Link 1](https://access.redhat.com/errata/RHSA-2023:1043), [Link 2](https://access.redhat.com/errata/RHSA-2023:1044), [Link 3](https://access.redhat.com/errata/RHSA-2023:1045).