Reflected XSS on clients-registrations endpoint
Package
Affected versions
>= 10.0.0, < 18.0.0
Patched versions
18.0.0
Description
Published to the GitHub Advisory Database
Apr 28, 2022
Reviewed
Apr 28, 2022
Last updated
Jan 7, 2023
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. When a malicious request is sent to the client registration endpoint, the error message is not properly escaped, allowing an attacker to execute malicious scripts into the user's browser.
Acknowledgement
Keycloak would like to thank Quentin TEXIER (Pentester at Opencyber) for reporting this issue.
References