CVE-2024-4028

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
Configurations

No configuration.

History

18 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 18:15

Updated : 2025-02-18 18:15


NVD link : CVE-2024-4028

Mitre link : CVE-2024-4028

CVE.ORG link : CVE-2024-4028


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation