CVE-2020-10748: Red Hat Keycloak

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

Affected products

  • Red Hat Keycloak: version 10.0.1 only
  • Red Hat Single Sign-On: before 7.4.1 (fixed in 7.4.1)

Published 2020-09-16. Last modified 2026-06-17.