Stored cross-site scripting in Keycloak - CVE-2022-2256
Published: October 5, 2022
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when handling roles functionality in the admin console. The vulnerability allows a privileged user to inject and execute arbitrary HTML and JavaScript code in victim's browser.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)
IBM i Modernization Engine for Lifecycle Integration
How to mitigate CVE-2022-2256
Red Hat Single Sign-On - update to 7.5.3
rh-sso7-keycloak (Red Hat package) - addressed in versions 15.0.8-1.redhat_00001.1.el7sso, 15.0.8-1.redhat_00001.1.el8sso
IBM i Modernization Engine for Lifecycle Integration - update to 1.4