Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
Moderate severity
GitHub Reviewed
Published
Dec 18, 2023
in
keycloak/keycloak
•
Updated Dec 18, 2023
Description
Published to the GitHub Advisory Database
Dec 18, 2023
Reviewed
Dec 18, 2023
Last updated
Dec 18, 2023
Keycloak prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This could permit an attacker to submit a specially crafted request leading to XSS or possibly further attacks.
References