CVE-2021-20195
Summary
| CVE | CVE-2021-20195 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-28 11:15:00 UTC |
| Updated | 2022-08-05 15:21:00 UTC |
| Description | A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
Risk And Classification
Problem Types: CWE-116
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1919143 – (CVE-2021-20195) CVE-2021-20195 keycloak: The Account console allows stored self-XSS via impersonation mechanism | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982347 Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-q6w2-89hq-hq27)