CVE Published: 26/10/2017 |
CVE Updated: 16/09/2024 |
CVE Year: 2017 Source: redhat |
Vendor: Red Hat, Inc. |
Product: keycloak Status : PUBLISHED
CVE-2017-12158 Description
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.