VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 33 minutes ago

CVE-2021-20323

6.1 Medium Mitigation candidate

Description

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

CWE-79 · Cross-site scripting

Exploitation Status

Working exploit published

A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 4 indexed Published artifacts you can open, in GitHub PoC, Nuclei; first seen 2022-12-07.
  • EPSS 37% chance in 30 days A model prediction, not an observation. Higher than 98% of all scored CVEs.

2 of these are GitHub repositories below the 5★ evidence bar. They are listed because a person may still want to open one; they do not count toward the exploit maturity above.

IndexArtifactStarsFirst seen
GitHub PoC ndmalc/CVE-2021-20323 13 2022-12-07
GitHub PoC A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. 3 2024-01-11
GitHub PoC Exploitation Scanner Cross Site Scripting vulnerability in Keycloak. 1 2024-07-07
Nuclei Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting

Waratek Defense Posture

Mitigation candidate

A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.

  • Protection none
  • Action unverified patch rule
  • Review automated inferred
  • Record active
Decided by patch-hint : A reference pointing at the upstream fix: a commit, a PR, a Red Hat bug
Finding Red Hat published an advisory () confirming a fix exists, and the linked Bugzilla ticket (https://bugzilla.redhat.com/show_bug.cgi?id=2013577) points to the upstream OpenJDK source patch. That makes this CVE a candidate for an ARMR patch rule. No rule exists and none is scheduled: whether one can be derived depends on reading the actual change.
Candidate fix https://bugzilla.redhat.com/show_bug.cgi?id=2013577 : a Red Hat bug: the triage, which links onward to the fix

CVSS

6.1 MEDIUM v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N NVD Primary published
CVSS 2.0 4.3 no band published AV:N/AC:M/Au:N/C:N/I:P/A:N NVD Primary

Affected Software & Releases

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.keycloak:keycloak-core 15.0.0 17.0.0 unbounded

🖥️ Product CPEs & Version Ranges

2 product(s) over 2 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
osv org.keycloak keycloak-core generic ≥ 15.0.0 and < 17.0.0
nvd redhat keycloak generic < 17.0.0

References

URLTags
https://bugzilla.redhat.com/show_bug.cgi?id=2013577 bugzilla
https://github.com/keycloak/keycloak PACKAGE

Timeline

Published 2022-03-25 Last modified 2026-06-17
Published2022-03-25By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.