<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:03:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05596</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05596</link>
      <description>bdu:2023-05596</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05596</guid>
    </item>
    <item>
      <title>EUVD-2026-187458</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187458</link>
      <description>EUVD-2026-187458</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187458</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1438</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1438</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1438</guid>
    </item>
    <item>
      <title>GHSA-w354-2f3c-qvg9 — Keycloak vulnerable to Cross-site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w354-2f3c-qvg9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;This issue is the result of code found in the exception here: [https://github.com/keycloak/keycloak/blob/48835576daa158443f69917ac309e1a7c951bc87/services/src/main/java/org/keycloak/authentication/AuthenticationProcessor.java#L1045](https://github.com/keycloak/keycloak/blob/48835576daa158443f69917ac309e1a7c951bc87/services/src/main/java/org/keycloak/authentication/AuthenticationProcessor.java#L1045)&lt;/p&gt;
&lt;p&gt;## Steps to reproduce&lt;/p&gt;
&lt;p&gt;When using the legacy admin console:&lt;/p&gt;
&lt;p&gt;1. Sign in as Admin user in first tab.
2. In that tab create new user in keycloak admin section &amp;gt; intercept user creation request and modify it by including malicious js script there (in username field).
3. Sign in as newly created user in second tab (same browser window but second tab).
4. Navigate back to first tab where you are signed in as admin, navigate to admin console which lists all application users.
5. Choose any user (except newly created malicious one) – modify anything for that user in his settings. E.g. navigate to credentials tab and set new credentials for him. Also set new password as temporary.
6. After update for that user is made, use impersonate option on that modified user.
7. You should see window with form which requires providing new credentials – fill it and submit request.
8. Just after submiting request u…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;This issue is the result of code found in the exception here: [https://github.com/keycloak/keycloak/blob/48835576daa158443f69917ac309e1a7c951bc87/services/src/main/java/org/keycloak/authentication/AuthenticationProcessor.java#L1045](https://github.com/keycloak/keycloak/blob/48835576daa158443f69917ac309e1a7c951bc87/services/src/main/java/org/keycloak/authentication/AuthenticationProcessor.java#L1045)&lt;/p&gt;
&lt;p&gt;## Steps to reproduce&lt;/p&gt;
&lt;p&gt;When using the legacy admin console:&lt;/p&gt;
&lt;p&gt;1. Sign in as Admin user in first tab.
2. In that tab create new user in keycloak admin section &amp;gt; intercept user creation request and modify it by including malicious js script there (in username field).
3. Sign in as newly created user in second tab (same browser window but second tab).
4. Navigate back to first tab where you are signed in as admin, navigate to admin console which lists all application users.
5. Choose any user (except newly created malicious one) – modify anything for that user in his settings. E.g. navigate to credentials tab and set new credentials for him. Also set new password as temporary.
6. After update for that user is made, use impersonate option on that modified user.
7. You should see window with form which requires providing new credentials – fill it and submit request.
8. Just after submiting request u…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w354-2f3c-qvg9</guid>
    </item>
    <item>
      <title>gsd-2022-1438</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1438</link>
      <description>gsd-2022-1438</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1438</guid>
    </item>
    <item>
      <title>RHSA-2023:1043 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update on RHEL 7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1043</link>
      <description>&lt;p&gt;bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods glob-parent: Regular Expression Denial of Service minimist: prototype pollution keycloak: HTML injection in execute-actions-email Admin REST API keycloak: XSS on impersonation under specific circumstances SnakeYaml: Constructor Deserialization Remote Code Execution Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations keycloak: Session takeover with OIDC offline refreshtokens keycloak: reflected XSS attack Moment.js: Path traversal  in moment.locale snakeyaml: Denial of Service due to missing nested depth limitation for collections moment: inefficient parsing algorithm resulting in DoS loader-utils: Regular expression denial of service snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or J…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods glob-parent: Regular Expression Denial of Service minimist: prototype pollution keycloak: HTML injection in execute-actions-email Admin REST API keycloak: XSS on impersonation under specific circumstances SnakeYaml: Constructor Deserialization Remote Code Execution Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations keycloak: Session takeover with OIDC offline refreshtokens keycloak: reflected XSS attack Moment.js: Path traversal  in moment.locale snakeyaml: Denial of Service due to missing nested depth limitation for collections moment: inefficient parsing algorithm resulting in DoS loader-utils: Regular expression denial of service snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or J…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1043</guid>
    </item>
  </channel>
</rss>
