Code injection in keycloak
High severity
GitHub Reviewed
Published
May 13, 2021
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Package
Affected versions
>= 9.0.0, < 12.0.3
Patched versions
12.0.3
Description
Published by the National Vulnerability Database
Mar 23, 2021
Reviewed
Mar 24, 2021
Published to the GitHub Advisory Database
May 13, 2021
Last updated
Jan 29, 2023
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References