Total vulnerabilities in the database
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
Software | From | Fixed in |
---|---|---|
![]() |
- | 21.1.2 |
redhat / keycloak | - | 21.1.2 |
redhat / single_sign-on | 7.6 | 7.6.4 |
redhat / openshift_container_platform | 4.11 | 4.11.x |
redhat / openshift_container_platform | 4.12 | 4.12.x |
redhat / openshift_container_platform_for_ibm_linuxone | 4.9 | 4.9.x |
redhat / openshift_container_platform_for_ibm_linuxone | 4.10 | 4.10.x |
redhat / openshift_container_platform_for_power | 4.9 | 4.9.x |
redhat / openshift_container_platform_for_power | 4.10 | 4.10.x |