A Stored XSS vulnerability was reported in the Keycloak Security mailing list, affecting all the versions of Keycloak, including the latest release (18.0.1). The vulnerability allows a privileged attacker to execute malicious scripts in the admin console, abusing of the default roles functionality.
Vector String: AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Vector Clarification:
Aytaç Kalıncı, Ilker Bulgurcu, Yasin Yılmaz (@aytackalinci, @smileronin, @yasinyilmaz) - NETAŞ PENTEST TEAM
{ "nvd_published_at": null, "github_reviewed_at": "2022-09-23T16:32:51Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }