org.keycloak:keycloak-ui-shared@26.3.3 vulnerabilities

  • latest version

    26.3.3

  • first published

    2 months ago

  • latest version published

    28 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.keycloak:keycloak-ui-shared package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the error_description query parameter, which is rendered directly on error pages without validation or sanitization. An attacker can display misleading messages within the trusted user interface by crafting URLs that include deceptive content, potentially tricking users into contacting malicious actors through phishing attempts.

    Note:

    The HTML encoding prevents XSS and makes this issue limited to phishing attempts.

    How to fix Cross-site Scripting (XSS)?

    There is no fixed version for org.keycloak:keycloak-ui-shared.

    [0,)