Junglewise Threat Intelligence

CVE-2024-53843: @dapperduckling/keycloak-connector-server reflected XSS in authentication URL handling

CVE-2024-53843 · Severity: low · CVSS 3.1 · Published 2024-11-26

Vendors: npm.

Executive brief

@dapperduckling/keycloak-connector-server is an authentication library used to integrate Keycloak identity services into applications. A reflected cross-site scripting (XSS) vulnerability in URL parameter handling allows attackers to craft malicious links that, when clicked by a user, execute arbitrary JavaScript in the victim's browser—potentially stealing session tokens, credentials, or sensitive data from the authenticated session.

Technical details

A reflected XSS vulnerability exists in the authentication flow due to improper sanitization of URL parameters. User-controlled input from the URL bar is reflected into the HTML response without adequate escaping, allowing an attacker to inject arbitrary JavaScript. The vulnerability requires user interaction (clicking a malicious link) and network access, but no authentication or privileges. An attacker can execute arbitrary JavaScript in the victim's browser within the security context of the application, potentially compromising session integrity and stealing sensitive data. The vulnerability has been patched in version 2.5.5 with proper input sanitization and escaping.

Affected products

  • dapperduckling keycloak-connector-server < 2.5.5

Timeline

  • 2024-11-26: disclosed
  • 2024-11-26: patched: Version 2.5.5

References