Reflected XSS using the oob endpoint on the RH-SSO
Issue
- Vulnerability could be used by an unauthenticated attacker to execute arbitrary code XSS/JavaScript.
Environment
- Red Hat Single Sign-On (RH-SSO)
- 7.5.x
- 7.6.x
- Docker image(keycloak 19.0.3)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.