CVE-2024-4028

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en KeyCloak. Este problema puede permitir que un atacante privilegiado use un payload malicioso como permiso al crear elementos (recursos y permisos) de la consola de administración, lo que lleva a un ataque Cross-Site Scripting (XSS) Almacenado.

18 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 18:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-4028

Mitre link : CVE-2024-4028

CVE.ORG link : CVE-2024-4028


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation