HTML Injection in Keycloak Admin REST API
Moderate severity GitHub Reviewed Published Feb 27, 2023 in keycloak/keycloak • Updated Dec 22, 2023
Description
Published to the GitHub Advisory Database Mar 1, 2023
Reviewed Mar 1, 2023
Published by the National Vulnerability DatabaseMar 29, 2023
Last updated Dec 22, 2023
The
execute-actions-emailendpoint of the Keycloak Admin REST API allows a malicious actor to send emails containing phishing links to Keycloak users.References