Vulnerability Name: | CVE-2022-2256 (CCN-235228) | ||||||||||||
Assigned: | 2022-08-04 | ||||||||||||
Published: | 2022-08-04 | ||||||||||||
Updated: | 2022-10-18 | ||||||||||||
Summary: | A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality. | ||||||||||||
CVSS v3 Severity: | 3.8 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N) 3.7 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N/E:H/RL:U/RC:R)
3.7 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N/E:H/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-2256 Source: CCN Type: Red Hat Bugzilla - Bug 2101942 (CVE-2022-2256) - CVE-2022-2256 keycloak: improper input validation permits script injection Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2101942 Source: XF Type: UNKNOWN keycloak-cve20222256-xss(235228) Source: CCN Type: Keycloak GIT Repository Keycloak Source: MISC Type: Broken Link, Third Party Advisory https://github.com/keycloak/keycloak/security/advisories/GHSA-w9mf-83w3-fv49 Source: CCN Type: IBM Security Bulletin 6848879 (i Modernization Engine for Lifecycle Integration) IBM i Modernization Engine for Lifecycle Integration is vulnerable to multiple vulnerabilities | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |