Description
Keycloak is vulnerable to XSS (cross-site scripting). The 'clients-registrations' endpoint does not properly sanitize user input. This vulnerability is not exploitable in the default configuration as it requires "Content-Type: application/json" in the request.
Remediation
Upgrade to the latest version of Keycloak
References
Related Vulnerabilities
WordPress Plugin GistPress Cross-Site Scripting (3.0.1)
WordPress Plugin Jock on air now Cross-Site Scripting (5.6.2)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-4721)
WordPress Plugin Travelpayouts:All Travel Brands in One Place Cross-Site Scripting (0.7.12)