VDB

BDU%3A2024-05694

BDU%3A2024-05694 PUBLISHED CVSS 6 MEDIUM

Уязвимость модуля единого входа в приложения (SAML) программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

Risk Scores

CVSS 3.1
6
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersions
Red Hat Inc.Jboss Fuse, JBoss Data Grid, Red Hat Single Sign-On, JBoss A-MQ, Data Grid, Red Hat Process Automation, Red Hat Integration Service Registry, Red Hat OpenShift GitOps, Decision Manager, Migration Toolkit for Applications, Red Hat Developer Hub, Red Hat Build of Keycloak
Red HatRHOSS-1.33-RHEL-81.33.0-5
Red HatRHOSS-1.33-RHEL-81.33.0-5
Red HatRed Hat Process Automation 7
Red HatRed Hat OpenShift GitOps
Red HatRed Hat build of Keycloak 2222-13
Red HatRed Hat build of Quarkus
Red HatRHOSS-1.33-RHEL-81.33.0-5
Red HatRed Hat build of Keycloak 2222-16
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack
Red HatRHOSS-1.33-RHEL-81.33.0-5
Red HatRed Hat build of Apicurio Registry 2
Red HatMigration Toolkit for Applications 7
Red HatRed Hat Single Sign-On 7
Red HatRHPAM 7.13.5 async
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRHOSS-1.33-RHEL-81.33.0-3
Red HatRed Hat AMQ Broker 7
Red HatRed Hat Fuse 7
Red HatRed Hat Developer Hub

…and 14 more

Timeline

  • Apr 25, 2024 CVE Published
  • Jul 24, 2024 CVE Updated
  • Mar 6, 2025 PoC Published
  • May 8, 2025 PoC Published
  • Mar 19, 2026 Distribution Patch
  • Mar 19, 2026 Distribution Patch
  • Mar 19, 2026 Distribution Patch
  • May 31, 2026 Distribution Patch
  • May 31, 2026 Distribution Patch
  • May 31, 2026 Security Advisory
  • May 31, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›