漏洞描述
Keycloak 10.0.0 to 18.0.0 contains a cross-site scripting vulnerability via the client-registrations endpoint. On a POST request, the application does not sanitize an unknown attribute name before including it in the error response with a 'Content-Type' of text/hml. Once reflected, the response is interpreted as HTML. This can be performed on any realm present on the Keycloak instance. Since the bug requires Content-Type application/json and is submitted via a POST, there is no common path to exploit that has a user impact.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/keycloak/keycloak/security/advisories/GHSA-m98g-63qj-fp8j↗bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2013577↗access.redhat.comhttps://access.redhat.com/security/cve/CVE-2021-20323↗github.comhttps://github.com/ndmalc/CVE-2021-20323↗github.comhttps://github.com/keycloak/keycloak/commit/3aa3db16eac9b9ed8c5335ac86f5f50e0c68662d↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-20323↗