Cross-site scripting in Keycloak - CVE-2022-0225
Published: October 5, 2022
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the group name while creating a new group from the admin console. A remote privileged user can inject and execute arbitrary HTML and JavaScript code in victim's browser.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Red Hat Single Sign-On
IBM i Modernization Engine for Lifecycle Integration
rh-sso7-keycloak (Red Hat package)
rh-sso7 (Red Hat package)
rh-sso7-javapackages-tools (Red Hat package)
How to mitigate CVE-2022-0225
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.1
Red Hat Single Sign-On - addressed in versions 7.5.3, 7.6.1
rh-sso7-keycloak (Red Hat package) - addressed in versions 15.0.8-1.redhat_00001.1.el7sso, 15.0.8-1.redhat_00001.1.el8sso, 18.0.3-1.redhat_00001.1.el7sso, 18.0.3-1.redhat_00001.1.el8sso
rh-sso7 (Red Hat package) - update to 1-5.el9sso
rh-sso7-javapackages-tools (Red Hat package) - update to 6.0.0-7.el9sso
External References
Related Security Bulletins
- Multiple vulnerabilities in Keycloak
- Multiple vulnerabilities in Red Hat Single Sign-On 7.5
- Red Hat Single Sign-On 7.5 on RHEL 8 update for keycloak
- Red Hat Single Sign-On 7.5 on RHEL 7 update for keycloak
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 9
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 8
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 7
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- XSS in IBM i Modernization Engine for Lifecycle Integration