← Back to browse · API

CVE-2022-4361

Severity
CRITICAL
CVSS
10.0
EPSS
0.00626
Risk score
40.22
CISA KEV
No
PoC
No
Published
2023-07-07
Modified
2024-11-12
First seen
2026-08-07
Aliases
EUVD-2023-1671, GHSA-3P62-6FJH-3P5H
Products
-
Sources
euvd EUVD-2023-1671

Description

Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.

References