Skip to main content

Improper Input Validation in org.keycloak:keycloak-core

CVE-2024-4028

  • org.keycloak:keycloak-core
Severity Low
Score 3.8/10

Summary

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored Cross-site scripting (XSS) attack.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • HIGH
  • LOW
  • NONE

CWE-20 - Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Advisory Timeline

  • Published