CVE-2024-4028
LOW3.8EPSS 0.20%Keycloak allows cross-site scripting (XSS)
發布日:2025/2/18修改日:2026/2/4
描述
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
受影響套件(1)
- Maven/org.keycloak:keycloak-corefrom 0, <= 26.1.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N |