CVE-2022-4361
CVSS V2 None
CVSS V3 None
Description
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
Overview
- CVE ID
- CVE-2022-4361
- Assigner
- redhat
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-07-07T19:57:44.567Z
- Last Modified Date
- 2023-07-07T19:57:44.567Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-4361 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4361 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 16:41:07 | Added to TrackCVE |