The vendor explicitly identifies these products as affected by this CVE.
- mta/mta-ui-rhel9 as a component of Migration Toolkit for Applications 6
- keycloak as a component of Red Hat build of Apicurio Registry 2
- keycloak as a component of Red Hat Data Grid 8
- keycloak as a component of Red Hat Decision Manager 7
- keycloak as a component of Red Hat Fuse 7
- keycloak as a component of Red Hat JBoss Data Grid 7
- keycloak as a component of Red Hat JBoss Enterprise Application Platform 6
- org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform 6
- rh-sso7-keycloak as a component of Red Hat JBoss Enterprise Application Platform 6
- openshift-gitops-1/gitops-rhel8-operator as a component of Red Hat OpenShift GitOps
- keycloak as a component of Red Hat Process Automation 7
- rh-sso7-keycloak as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.
- Remediation
- See the Red Hat OpenShift serverless 1.33 documentation at: https://access.redhat.com/documentation/en-us/red_hat_openshift_serverless/1.33
