CVE Published: 25/09/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Single Sign-On 7 Status : PUBLISHED
CVE-2022-4137 Description
A reflected cross-site scripting (XSS) vulnerability was found in the \'oob\' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing it to be changed or collected by an attacker.