CVE-2024-4028
CVSS 3.1 Score 3.8 of 10 (low)
Details
Published Feb 18, 2025
CWE ID 20
Summary
CVE-2024-4028 is a newly identified vulnerability affecting Keycloak. It allows privileged attackers to introduce malicious scripts by creating items, such as Resources and Permissions, in the admin console. By injecting these scripts, an XSS attack can be executed, compromising the security of the affected system. The vulnerability poses a significant risk, especially in environments where admin privileges are not adequately controlled. It is crucial to update Keycloak to its latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share