Description
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1924606
Related Vulnerabilities
CVE-2019-18954 Vulnerability in npm package pomelo
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_3
CVE-2022-36899 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations
CVE-2023-28674 Vulnerability in maven package org.jenkinsci.plugins:octoperf
CVE-2013-2165 Vulnerability in maven package org.richfaces:richfaces