CVE-2022-1438

Source
https://cve.org/CVERecord?id=CVE-2022-1438
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1438.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-1438
Aliases
Downstream
Withdrawn
2026-03-18T01:26:18.422750Z
Published
2023-09-20T14:15:12.607Z
Modified
2026-03-18T01:26:18.422750Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1438.json"