It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1697 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2020-02-10T14:13:58

Updated: 2020-02-10T14:13:58

Reserved: 2019-11-27T00:00:00


Link: CVE-2020-1697

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-02-10T15:15:21.497

Modified: 2023-11-07T03:19:27.053


Link: CVE-2020-1697

JSON object: View

cve-icon Redhat Information

No data.

CWE