CVE-2022-1274
published 2023-03-29CVE-2022-1274: A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.69%
49.0th percentile
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 20.0.5 | 20.0.5 |
| redhat | keycloak | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | single_sign-on | >= 7.6 < 7.6.2 | 7.6.2 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: HTML injection in execute-actions-email Admin REST API
vendor_redhat·2023-02-28·CVSS 5.4
CVE-2022-1274 [MEDIUM] CWE-80 keycloak: HTML injection in execute-actions-email Admin REST API
keycloak: HTML injection in execute-actions-email Admin REST API
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
OSV
HTML Injection in Keycloak Admin REST API
osv·2023-03-01
CVE-2022-1274 [MEDIUM] HTML Injection in Keycloak Admin REST API
HTML Injection in Keycloak Admin REST API
The `execute-actions-email` endpoint of the Keycloak Admin REST API allows a malicious actor to send emails containing phishing links to Keycloak users.
GHSA
HTML Injection in Keycloak Admin REST API
ghsa·2023-03-01
CVE-2022-1274 [MEDIUM] CWE-79 HTML Injection in Keycloak Admin REST API
HTML Injection in Keycloak Admin REST API
The `execute-actions-email` endpoint of the Keycloak Admin REST API allows a malicious actor to send emails containing phishing links to Keycloak users.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2073157https://github.com/keycloak/keycloak/security/advisories/GHSA-m4fv-gm5m-4725https://herolab.usd.de/security-advisories/usd-2021-0033/https://bugzilla.redhat.com/show_bug.cgi?id=2073157https://github.com/keycloak/keycloak/security/advisories/GHSA-m4fv-gm5m-4725https://herolab.usd.de/security-advisories/usd-2021-0033/
2023-03-29
Published