Description
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
Exploits (1)
nomisec
WORKING POC
by shoucheng3 · poc
https://github.com/shoucheng3/keycloak__keycloak_CVE-2022-1274_20-0-3
Scores
CVSS v3
5.4
EPSS
0.0098
EPSS Percentile
76.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Lab Environment
COMMUNITY
Community Lab
Details
CWE
CWE-80
CWE-79
Status
published
Products (6)
org.keycloak/keycloak-services
0 - 20.0.5Maven
redhat/keycloak
< 20.0.5
redhat/openshift_container_platform
4.9
redhat/openshift_container_platform
4.10
redhat/single_sign-on
redhat/single_sign-on
7.6 - 7.6.2
Published
Mar 29, 2023
Tracked Since
Feb 18, 2026