Looking for the vulnerability index of Invicti's legacy products?
Keycloak clients-registrations XSS (CVE-2021-20323) - Vulnerability Database

Keycloak clients-registrations XSS (CVE-2021-20323)

Description

Keycloak is vulnerable to XSS (cross-site scripting). The 'clients-registrations' endpoint does not properly sanitize user input. This vulnerability is not exploitable in the default configuration as it requires "Content-Type: application/json" in the request.

Remediation

Upgrade to the latest version of Keycloak

Related Vulnerabilities