CVE-2024-4028 is a stored Cross-Site Scripting (XSS) vulnerability in Keycloak, allowing a privileged attacker to inject malicious payloads when creating resources or permissions via the admin console. This vulnerability has a low CVSS score of 3.8, indicating low impact on confidentiality and integrity, with no user interaction required for exploitation. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Single Sign-On 7 | All Versions ImpactedCNA affecteddefault affected | |
| Https://Github.Com/Keycloak/Keycloak | Keycloak | >= 18.0.8, < 18.0.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.