CVE-2022-0225
26.08.2022, 18:15
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
Vendor | Product | Version |
---|---|---|
redhat | keycloak | - |
redhat | single_sign-on | 7.0 |
𝑥
= Vulnerable software versions