Back to search
CVE-2017-12158
Published: Oct 26, 2017
Modified: Sep 16, 2024
PUBLISHED
Description
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.
| Vendor | Product | Versions |
|---|---|---|
Red Hat, Inc. | keycloak | affected 3.4.0 |
Weaknesses (CWE)
References
RHSA-2017:2904
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2905
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2906
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1489161
x_refsource_CONFIRM
101618
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now