Severity
3.8LOW
EPSS
0.9%
top 24.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 1
Latest updateDec 24

Description

A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:NExploitability: 1.2 | Impact: 2.5

Affected Packages3 packages

CVEListV5keycloakkeycloak as shipped in Red Hat Single Sign-On 7

🔴Vulnerability Details

4
OSV
mrp: introduce active flags to prevent UAF when applicant uninit2025-12-24
GHSA
Keycloak vulnerable to Stored Cross site Scripting (XSS) when loading default roles2022-09-23
OSV
Keycloak vulnerable to Stored Cross site Scripting (XSS) when loading default roles2022-09-23
CVEList
CVE-2022-2256: A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 72022-09-01

📋Vendor Advisories

2
Red Hat
kernel: tipc: check attribute length for bearer name2025-02-26
Red Hat
keycloak: improper input validation permits script injection2022-06-28
CVE-2022-2256 (LOW CVSS 3.8) | A Stored Cross-site scripting (XSS) | cvebase.io