CVE-2021-20323A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
CWE-79 · Cross-site scripting
Working exploit published
A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| GitHub PoC | ndmalc/CVE-2021-20323 | 13 | 2022-12-07 |
| GitHub PoC | A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. | 3 | 2024-01-11 |
| GitHub PoC | Exploitation Scanner Cross Site Scripting vulnerability in Keycloak. | 1 | 2024-07-07 |
| Nuclei | Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting |
A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.
| Decided by | patch-hint : A reference pointing at the upstream fix: a commit, a PR, a Red Hat bug |
|---|---|
| Finding | Red Hat published an advisory () confirming a fix exists, and the linked Bugzilla ticket (https://bugzilla.redhat.com/show_bug.cgi?id=2013577) points to the upstream OpenJDK source patch. That makes this CVE a candidate for an ARMR patch rule. No rule exists and none is scheduled: whether one can be derived depends on reading the actual change. |
| Candidate fix | https://bugzilla.redhat.com/show_bug.cgi?id=2013577 : a Red Hat bug: the triage, which links onward to the fix |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
NVD | Primary | published |
| CVSS 2.0 | 4.3 | no band published | AV:N/AC:M/Au:N/C:N/I:P/A:N |
NVD | Primary |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.keycloak:keycloak-core |
15.0.0 | 17.0.0 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| osv | org.keycloak | keycloak-core | generic | ≥ 15.0.0 and < 17.0.0 |
| nvd | redhat | keycloak | generic | < 17.0.0 |
| URL | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2013577 | bugzilla |
| https://github.com/keycloak/keycloak | PACKAGE |
| Published | 2022-03-25 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |