ZeroHour

CVE-2020-1697

CVSS 3.1
5.4 medium
EPSS
<1%p53
Published
()
Modified
Description

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

Vendors
redhat
Products
keycloak, single sign-on
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.