Description
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1847428
Related Vulnerabilities
CVE-2022-41243 Vulnerability in maven package com.smalltest:smalltest
CVE-2020-7013 Vulnerability in npm package kibana
CVE-2020-10748 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2022-28731 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2022-33140 Vulnerability in maven package org.apache.nifi:nifi-shell-authorizer