A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.keycloak:keycloak-services(Maven) | 0 | 22.0.9 | N/A |
| org.keycloak:keycloak-services(Maven) | 23.0.0 | 23.0.5 | N/A |
CVSS Metrics