
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2021-20195) was discovered in Keycloak versions prior to 13.0.0. The flaw involves a Self Stored XSS (Cross-Site Scripting) attack vector that could potentially lead to complete account takeover. The vulnerability was identified due to user-supplied data fields not being properly encoded when JavaScript code processes the data (CVE Database).
The vulnerability specifically affects the Account page where user first name and last name fields are not properly HTML-encoded. This allows malicious HTML code containing JavaScript to be embedded into the Account page. The vulnerability becomes particularly dangerous when combined with the Impersonation functionality, which can be exploited through the Keycloak admin browser (Red Hat Bugzilla).
The primary impact of this vulnerability is the potential for complete account takeover. The highest threats from this vulnerability affect data confidentiality, integrity, and system availability. When successfully exploited, an attacker could compromise the Keycloak system through the admin browser (CVE Database).
The vulnerability can be exploited through a combination of stored XSS and the impersonation mechanism. While the malicious JavaScript code is initially linked to the attacker's user account (Self-XSS), it can be escalated to affect admin privileges through the Keycloak impersonation functionality (Red Hat Bugzilla).
Several mitigation strategies have been recommended: 1) HTML encode the user first name and last name fields to prevent execution of embedded code, 2) Implement Content Security Policy (CSP) browser protection mechanism, 3) Redesign realms separation to make each realm accessible by different subdomains, utilizing Same Origin Policy (SOP) browser protection mechanism to limit attacker capabilities. The vulnerability has been fixed in Keycloak version 13.0.0 (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."