CVE-2020-1697
published 2020-02-10CVE-2020-1697: It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.76%
51.2th percentile
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 9.0.0 | 9.0.0 |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
XSS in Keycloak
osv·2020-04-15
CVE-2020-1697 [MEDIUM] XSS in Keycloak
XSS in Keycloak
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
GHSA
XSS in Keycloak
ghsa·2020-04-15
CVE-2020-1697 [MEDIUM] CWE-79 XSS in Keycloak
XSS in Keycloak
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
Red Hat
keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)
vendor_redhat·2020-07-02·CVSS 6.1
CVE-2020-10748 [MEDIUM] CWE-79 keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)
keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
A flaw was found in Keycloak's data filter, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
Package: keycloak (Red Hat Decision Manager 7) - Not affected
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: keycloak (Red Hat Process Automation 7) - Not affected
Package: rh-sso7-keycloak (Re
Red Hat
keycloak: stored XSS in client settings via application links
vendor_redhat·2020-02-05·CVSS 6.1
CVE-2020-1697 [MEDIUM] CWE-79 keycloak: stored XSS in client settings via application links
keycloak: stored XSS in client settings via application links
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
A flaw was found during the assessment of the Admin Console application for Keycloak, where it was found that Application Links to external applications are not validated properly. An attacker could use this flaw to cause Stored XSS attacks.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
Package: keycloak (Red Hat OpenShift Application Runtime
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10748 keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)
bugzilla·2020-05-18·CVSS 6.1
CVE-2020-10748 [MEDIUM] CVE-2020-10748 keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)
CVE-2020-10748 keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697)
Insufficient filtering of Client baseUrl (follow-up to CVE-2020-1697)
https://issues.redhat.com/browse/KEYCLOAK-14149
Discussion:
Acknowledgments:
Name: Lauritz Holtmann (Chair for Network and Data Security at Ruhr University Bochum)
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4.1
Via RHSA-2020:2813 https://access.redhat.com/errata/RHSA-2020:2813
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-10748
Bugzilla
CVE-2020-1697 keycloak: stored XSS in client settings via application links
bugzilla·2020-01-16·CVSS 6.1
CVE-2020-1697 [MEDIUM] CVE-2020-1697 keycloak: stored XSS in client settings via application links
CVE-2020-1697 keycloak: stored XSS in client settings via application links
During the assessment of the Admin Console application, it was found that links to external applications, so called Application Links, does not get validated properly and therefore are prone to Stored XSS attacks. The affected parameter BaseURL within the Clients settings page from the admin console application accepts any characters and therefore it is possible to insert URLs with the javascript
https://issues.redhat.com/browse/KEYCLOAK-12459
Discussion:
Acknowledgments:
Name: Cure53 Berlin
---
This issue has been addressed in the following products:
Red Hat Runtimes Spring Boot 2.2.6
Via RHSA-2020:2252 https://access.redhat.com/errata/RHSA-2020:2252
---
This bug is now closed. Further updates for indiv
2020-02-10
Published