VDB

CVE-2017-12158

CVE-2017-12158 PUBLISHED CVSS 3.5 LOW

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

EPSS 0.67% · 71.7th percentile

Risk Scores

CVSS 2.0
3.5
EPSS Score
0.67%
71.7th percentile

Affected Products

VendorProductVersions
Red Hat, Inc.keycloak3.4.0
redhatsingle_sign_on7.0, 7.1
keycloakkeycloak
Mavenorg.keycloak:keycloak-parent0

Timeline

  • Oct 26, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›