Description
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1847428
Related Vulnerabilities
CVE-2022-40705 Vulnerability in maven package soap:soap
CVE-2022-43441 Vulnerability in npm package sqlite3
CVE-2018-14719 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-43801 Vulnerability in npm package mercurius
CVE-2022-44729 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge