Description
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1847428
Related Vulnerabilities
CVE-2013-2165 Vulnerability in maven package org.richfaces.framework:richfaces-impl
CVE-2020-2290 Vulnerability in maven package org.biouno:uno-choice
CVE-2019-10172 Vulnerability in maven package org.codehaus.jackson:jackson-mapper-asl
CVE-2023-0044 Vulnerability in maven package io.quarkus:quarkus-vertx-http
CVE-2020-25803 Vulnerability in maven package org.craftercms:crafter-studio