ZeroHour

CVE-2022-1274

CVSS 3.1
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

Vendors
redhat
Products
keycloak, single sign-on, openshift container platform
Weakness
CWE-80, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.