Back

LOW

Keycloak-core: stored xss in keycloak when creating a items in admin console

Published Feb 18, 2025

Description

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.

Affected products

Remediation

Vendor solution

Currently the is no mitigation available for this vulnerability.

Red Hat statement

Red Hat rates this as a Low impact since this requires previous high privileged administrator account to perform this operation.

Red Hat mitigation

Currently the is no mitigation available for this vulnerability.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Feb 18, 2025
Updated Nov 21, 2025
Reserved Apr 22, 2024

CISA Vulnrichment

Updated Feb 18, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Feb 18, 2025
Bugzilla 2276418

ENISA EUVD

Assigner redhat
Published Feb 18, 2025
Updated Nov 21, 2025