Required CVE Record Information
Description
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
3.8 | LOW | 3.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N |
Product Status
Learn moreVersions 1 Total
Default Status: unaffected
affected
Versions 0 Total
Default Status: All versions are unaffected
Versions 0 Total
Default Status: All versions are affected
References 2 Total
- https://access.redhat.com/security/cve/CVE-2024-4028 vdb-entry
- bugzilla.redhat.com: RHBZ#2276418 issue-tracking