Description
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=2073157
https://github.com/keycloak/keycloak/security/advisories/GHSA-m4fv-gm5m-4725
https://herolab.usd.de/security-advisories/usd-2021-0033/
Related Vulnerabilities
CVE-2021-41182 Vulnerability in maven package org.webjars:jquery-ui
CVE-2021-41183 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2022-24373 Vulnerability in npm package react-native-reanimated
CVE-2020-7238 Vulnerability in maven package io.netty:netty-codec-http
CVE-2022-25881 Vulnerability in npm package http-cache-semantics