Description
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1847428
Related Vulnerabilities
CVE-2017-16129 Vulnerability in npm package superagent
CVE-2022-36097 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-ui
CVE-2022-45378 Vulnerability in maven package soap:soap
CVE-2019-1010266 Vulnerability in npm package lodash
CVE-2023-37582 Vulnerability in maven package org.apache.rocketmq:rocketmq-namesrv