Keycloak Cross-site Scripting on OpenID connect login service
Description
Published to the GitHub Advisory Database
Mar 1, 2023
Reviewed
Mar 1, 2023
Published by the National Vulnerability Database
Sep 25, 2023
Last updated
Nov 8, 2023
A reflected cross-site scripting (XSS) vulnerability was found in the
oob
OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page.References