CVE-2022-0225
published 2022-08-26CVE-2022-0225: A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
2.73%
84.4th percentile
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
vim: use-after-free in find_var_also_in_script() in evalvars.c
vendor_redhat·2022-08-16·CVSS 7.8
CVE-2022-2889 [HIGH] CWE-416 vim: use-after-free in find_var_also_in_script() in evalvars.c
vim: use-after-free in find_var_also_in_script() in evalvars.c
Use After Free in GitHub repository vim/vim prior to 9.0.0225.
A use-after-free vulnerability was found in Vim in the find_var_also_in_script function in the evalvars.c file. This issue occurs because an already freed memory is used when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the use-after-free, causing the application to crash, possibly executing code and corrupting memory.
Statement: Red Hat Product Security has rated this issue as having a Low security impact because the user has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random
Red Hat
keycloak: Stored XSS in groups dropdown
vendor_redhat·2022-01-13·CVSS 5.4
CVE-2022-0225 [MEDIUM] CWE-79 keycloak: Stored XSS in groups dropdown
keycloak: Stored XSS in groups dropdown
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
OSV
Keycloak XSS via use of malicious payload as group name when creating new group from admin console
osv·2022-08-27
CVE-2022-0225 [MEDIUM] Keycloak XSS via use of malicious payload as group name when creating new group from admin console
Keycloak XSS via use of malicious payload as group name when creating new group from admin console
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
GHSA
Keycloak XSS via use of malicious payload as group name when creating new group from admin console
ghsa·2022-08-27
CVE-2022-0225 [MEDIUM] CWE-79 Keycloak XSS via use of malicious payload as group name when creating new group from admin console
Keycloak XSS via use of malicious payload as group name when creating new group from admin console
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-26
Published