Files
CVEs-PoC/2022/CVE-2022-4137.md
T
2025-09-29 21:09:30 +02:00

1.3 KiB

CVE-2022-4137

Description

A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing it to be changed or collected by an attacker.

POC

Reference

No PoCs from references.

Github