JBoss KeyCloak CVE-2017-12158 Cross Site Scripting Vulnerability
BID:101618
Info
JBoss KeyCloak CVE-2017-12158 Cross Site Scripting Vulnerability
| Bugtraq ID: | 101618 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12158 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2017 12:00AM |
| Updated: | Dec 19 2017 09:00PM |
| Credit: | Mykhailo Stadnyk (Playtech) |
| Vulnerable: |
Redhat Single Sign-On 7.1 for RHEL 6 Server 0 Redhat Single Sign-On 7.1 for RHEL 7 Serve Redhat Single Sign-On 7.1 Redhat Single Sign-On 7.0 Jboss KeyCloak 0 |
| Not Vulnerable: | |
Exploit / POC
JBoss KeyCloak CVE-2017-12158 Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.