CVE Published: 13/11/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: redhat |
Vendor: Red Hat |
Product: keycloak Status : PUBLISHED
CVE-2018-14655 Description
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using \'response_mode=form_post\' it is possible to inject arbitrary Javascript-Code via the \'state\'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.