The vendor explicitly identifies these products or versions as containing the fix.
- rhbk/keycloak-operator-bundle@sha256:1696b6f86abea123341f703981c26d79365c8a0c046d7add6970fb7b1848ace2_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:1f1063865b03fc7df0cde72bf9adad052c1344681c68d251d90a66bf17d2ead5_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:5c7682f2c9ad3abc538c452e2c1b529ebbdc3325c61f9749c02c653b9b0305d1_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:807b9465c2d0b562e44fbba308674ff0b7407525b508eba70189e98a74571577_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:3958d590802fbd607139edcc2bfdbd4c84c20da2ecb823e2ddc78c47d0fe9cb9_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:84220c0ea3f46801293efa2539a77bf0f84464b2acc966878ee199db1a61c016_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:bbf03f6b8636dd6fbbf8714ca18b5e2857977375660e8f0f212009655eaa5bdb_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-operator-bundle@sha256:a588a2eed385d29ccaf1f81bd719ca4b4ee85ab7359081706b2e810fd5e2db79_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:37e61c0daec97796ceb9899a7104a40723ab5fe7c147c7dca928171190d68cde_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:481dd9a0fabf5afe085f2d5af3b0cbf6a16c28a02dfde8dbbeb1bc406a377087_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:8409c7a684aaee2080a718ea1b38d32cad93ae677db831fdaa98caa70e7ca18f_arm64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:d1318bc91903f9374c2403f9845b1ef1b63ca1566a553eb51b7073c1737feeee_ppc64le as a component of Red Hat build of Keycloak 26.2
- Summary
- A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake support phone numbers or URLs), which are displayed within the trusted Keycloak UI. This creates a phishing vector, potentially tricking users into contacting malicious actors.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
