Security Advisory

CVE-2022-2256

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-09-01 19:57:29
Last updated 2024-08-03 00:32:09
Assigner redhat
State PUBLISHED

Description

A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.