CVE-2022-1274

MEDIUM LAB

Redhat Keycloak < 20.0.5 - Basic XSS

Title source: rule

Description

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

Exploits (1)

nomisec WORKING POC
by shoucheng3 · poc
https://github.com/shoucheng3/keycloak__keycloak_CVE-2022-1274_20-0-3

Scores

CVSS v3 5.4
EPSS 0.0098
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull registry.access.redhat.com/ubi8-minimal
docker pull registry:2
docker pull jboss/base-jdk:8
docker pull google/cadvisor:v0.26.1
docker pull grafana/grafana:4.4.3

Details

CWE
CWE-80 CWE-79
Status published
Products (6)
org.keycloak/keycloak-services 0 - 20.0.5Maven
redhat/keycloak < 20.0.5
redhat/openshift_container_platform 4.9
redhat/openshift_container_platform 4.10
redhat/single_sign-on
redhat/single_sign-on 7.6 - 7.6.2
Published Mar 29, 2023
Tracked Since Feb 18, 2026