Description
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1847428
Related Vulnerabilities
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-management
CVE-2019-10380 Vulnerability in maven package org.jenkins-ci.plugins:simple-travis-runner
CVE-2017-12963 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-29894 Vulnerability in npm package strapi
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka_2.12