{"id":"GHSA-m98g-63qj-fp8j","summary":"Reflected XSS on clients-registrations endpoint","details":"A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. When a malicious request is sent to the client registration endpoint, the error message is not properly escaped, allowing an attacker to execute malicious scripts into the user's browser.\n\n### Acknowledgement\n\nKeycloak would like to thank Quentin TEXIER (Pentester at Opencyber) for reporting this issue.","modified":"2024-11-28T05:40:56.914808Z","published":"2022-04-28T21:01:28Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-04-28T21:01:28Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/keycloak/keycloak/security/advisories/GHSA-m98g-63qj-fp8j"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"}],"affected":[{"package":{"name":"org.keycloak:keycloak-parent","ecosystem":"Maven","purl":"pkg:maven/org.keycloak/keycloak-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"18.0.0"}]}],"versions":["10.0.0","10.0.1","10.0.2","11.0.0","11.0.1","11.0.2","11.0.3","12.0.0","12.0.1","12.0.2","12.0.3","12.0.4","13.0.0","13.0.1","14.0.0","15.0.0","15.0.1","15.0.2","15.1.0","15.1.1","16.0.0","16.1.0","16.1.1","17.0.0","17.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m98g-63qj-fp8j/GHSA-m98g-63qj-fp8j.json"}}],"schema_version":"1.9.0"}