← Back to CVE List

CVE-2017-12158

Published: 2017-10-26T17:29Z
Last Modified: 2024-11-21T03:08Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt