Back to search
CVE-2022-2256
Published: Sep 1, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.
| Vendor | Product | Versions |
|---|---|---|
n/a | keycloak | affected keycloak as shipped in Red Hat Single Sign-On 7 |
Weaknesses (CWE)
References
https://bugzilla.redhat.com/show_bug.cgi?id=2101942
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now