ZeroHour

CVE-2021-20222

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
Description

A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vendors
redhat
Products
keycloak
Weakness
CWE-20, CWE-79
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.