CVE-2022-4361: Red Hat Keycloak

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.

Affected products

  • Red Hat Keycloak: before 21.1.2 (fixed in 21.1.2)
  • Red Hat Openshift Container Platform: version 4.11 only; version 4.12 only
  • Red Hat Openshift Container Platform For IBM Linuxone: version 4.9 only; version 4.10 only
  • Red Hat Openshift Container Platform For Power: version 4.9 only; version 4.10 only
  • Red Hat Single Sign-On: from 7.6, before 7.6.4 (fixed in 7.6.4); affected versions not specified

Published 2023-07-07. Last modified 2026-06-17.