Description
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1847428
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2018-8041 Vulnerability in maven package org.apache.camel:camel-mail
CVE-2020-2259 Vulnerability in maven package org.jenkins-ci.plugins:computer-queue-plugin
CVE-2021-45459 Vulnerability in npm package node-windows
CVE-2023-34212 Vulnerability in maven package org.apache.nifi:nifi-jms-processors