REDHAT-BUG-2249673: XSS
Published Nov 14, 2023
·Updated
Keycloak prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This could permit an attacker to submit a specially crafted request leading to XSS or possibly further attacks.
Affected Software
1 affected component
Red Hat Keycloak
Event History
Nov 14, 2023
Data Sourced
via Red Hat·06:51 PM
DescriptionSeverityAffected Software