CVE-2020-10748
16.09.2020, 18:15
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
Vendor | Product | Version |
---|---|---|
redhat | keycloak | 10.0.1 |
redhat | single_sign-on | 𝑥 < 7.4.1 |
𝑥
= Vulnerable software versions