312
VMScore

CVE-2018-14655

Published: 13/11/2018 Updated: 09/10/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak 4.0.0

redhat keycloak 4.3.0

redhat keycloak 3.4.3

redhat single_sign-on 7.2

redhat single sign-on -

Vendor Advisories

Synopsis Moderate: Red Hat Single Sign-On 725 security and bug fix update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 72 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Com ...
Synopsis Moderate: Red Hat Single Sign-On 725 on RHEL 6 security and bug fix update Type/Severity Security Advisory: Moderate Topic New Red Hat Single Sign-On 725 packages are now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Moder ...
Synopsis Moderate: Red Hat Single Sign-On 725 on RHEL 7 security and bug fix update Type/Severity Security Advisory: Moderate Topic New Red Hat Single Sign-On 725 packages are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moder ...
A flaw was found in Keycloak 343Final, 400Beta2, 430Final When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL This allows an XSS-Attack upon succesfully login ...

Github Repositories

Keycloak security scanner

keycloak-scanner Introduction This scanner scan keycloak for known vulnerabilities Installation pip install --upgrade keycloak-scanner Example $ git clone githubcom/NeuronAddict/keycloak-scanner $ cd keycloak-scanner $ docker-compose -f itests/docker-composeyml up -d $ python3 itests/wait-docker-composepy # just wait keycloak