CVE-2024-4028: Keycloak-core: stored xss in keycloak when creating a items in admin console
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
Other sources
This flaw allows a privileged attacker to use the malicious payload as the permission while creating a new permission or resource from the admin console, leading to a stored Cross-site scripting (XSS) attack.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4028?
CVE-2024-4028 is considered a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-4028?
To mitigate CVE-2024-4028, it is recommended to update the Keycloak software to the latest patched version provided by Red Hat.
Who is affected by CVE-2024-4028?
CVE-2024-4028 affects users of Red Hat Build of Keycloak, particularly those with permissions to create resources and permissions.
What exploit can CVE-2024-4028 enable?
CVE-2024-4028 can enable a privileged attacker to execute a stored XSS payload through the Keycloak admin console.
When was CVE-2024-4028 reported?
CVE-2024-4028 was reported in 2024, highlighting a critical vulnerability in the Keycloak admin interface.