CVE-2022-1274 PUBLISHED CVSS 5.400000095367432 MEDIUM

Reported by redhat · Published March 29, 2023

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

Risk Scores

CVSS v3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
n/akeycloakunknown
n/akeycloakunknown, unknown, unknown
Mavenorg.keycloak:keycloak-core0, 0, 0

Timeline

References

Open in Interactive Console →