Description
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199
Related Vulnerabilities
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service
CVE-2022-24948 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2017-1000498 Vulnerability in maven package com.caverock:androidsvg
CVE-2017-16021 Vulnerability in npm package uri-js
CVE-2023-27480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-xar-model