{"id":"GHSA-m98g-63qj-fp8j","aliases":[],"url":"https://o3.security/vulnerability/GHSA-m98g-63qj-fp8j","summary":"Reflected XSS on clients-registrations endpoint","details":"A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. When a malicious request is sent to the client registration endpoint, the error message is not properly escaped, allowing an attacker to execute malicious scripts into the user's browser.\n\n### Acknowledgement\n\nKeycloak would like to thank Quentin TEXIER (Pentester at Opencyber) for reporting this issue.","published":"2022-04-28T21:01:28Z","modified":"2024-11-28T05:40:56.914808Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-parent","fixedVersion":"18.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/keycloak/keycloak/security/advisories/GHSA-m98g-63qj-fp8j"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:40:56.914808Z"}}