Loading HuntDB...

GHSA-fqc7-5xxc-ph7r

GitHub Security Advisory

Keycloak XSS via use of malicious payload as group name when creating new group from admin console

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.

Affected Packages

Maven org.keycloak:keycloak-core
Affected versions: 0 (last affected: 16.1.0)

Related CVEs

Key Information

GHSA ID
GHSA-fqc7-5xxc-ph7r
Published
August 27, 2022 12:00 AM
Last Modified
September 2, 2022 6:06 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.keycloak:keycloak-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 1, 2025 6:44 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.