keycloak: stored XSS in client settings via application links
Published Feb 10, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.76%
Description
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
Affected products
-
- Version All versions before 9.0.0StatusaffectedConstraints-
- Version
Configuration 2
- 7.3
No data.
Red Hat Runtimes Spring Boot 2.2.6
keycloak
Fixed · RHSA-2020:2252
Red Hat Single Sign-On 7.3
n/a
Fixed · RHSA-2020:0445
Text-Only RHOAR
n/a
Fixed · RHSA-2020:2905
Red Hat Fuse 7
keycloak
Not affected
Red Hat Mobile Application Platform 4
keycloak
Out of support scope
Red Hat OpenShift Application Runtimes
keycloak
Affected
Red Hat Single Sign-On 7
rh-sso7-keycloak
Affected
Red Hat support for Spring Boot
keycloak
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Runtimes Spring Boot 2.2.6 | keycloak | Fixed | RHSA-2020:2252 |
| Red Hat Single Sign-On 7.3 | n/a | Fixed | RHSA-2020:0445 |
| Text-Only RHOAR | n/a | Fixed | RHSA-2020:2905 |
| Red Hat Fuse 7 | keycloak | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | keycloak | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | keycloak | Affected | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Affected | n/a |
| Red Hat support for Spring Boot | keycloak | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2020-1697 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1791538 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1697 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0373 Advisory
- https://github.com/advisories/GHSA-8vf3-4w62-m3pq Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1697
- https://www.cve.org/CVERecord?id=CVE-2020-1697
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-1697 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1791538 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1697 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0373 | Advisory | |
| https://github.com/advisories/GHSA-8vf3-4w62-m3pq | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-1697 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-1697 |
Change history (0)
No recorded changes yet.