Vulnerability Name: | CVE-2022-0225 (CCN-234602) | ||||||||||||
Assigned: | 2022-08-04 | ||||||||||||
Published: | 2022-08-04 | ||||||||||||
Updated: | 2022-09-01 | ||||||||||||
Summary: | A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack. | ||||||||||||
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
7.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.3 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:M/C:C/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-0225 Source: CCN Type: Red Hat Bugzilla - Bug 2040268 (CVE-2022-0225) - CVE-2022-0225 keycloak: Stored XSS in groups dropdown Source: MISC Type: Exploit, Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2040268 Source: XF Type: UNKNOWN keycloak-cve20220225-xss(234602) Source: CCN Type: Keycloak GIT Repository Stored XSS in groups dropdown Source: MISC Type: Broken Link https://github.com/keycloak/keycloak/security/advisories/GHSA-755v-r4x4-qf7m Source: CCN Type: IBM Security Bulletin 6991217 (i Modernization Engine for Lifecycle Integration) IBM i Modernization Engine for Lifecycle Integration is vulnerable to cross-site scripting (CVE-2022-0225) Source: CCN Type: Mend Vulnerability Database CVE-2022-0225 Source: CCN Type: Mend Vulnerability Database WS-2022-0408 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |