Skip to content

BCheck: CVE-2021-20323 is not detecting fixed versions #208

Description

@GanbaruTobi

Current behavior

The check says that keycloak is vulnerable

Expected behavior

No warning for fixed versions

Motivation for change

Its not working as expected

Environment details

  • Burp version: 2024.4.2
  • BCheck language version:
  • Operating System: Linux

Additional details

The response contains an escaped xss payload instead of an unescaped:
...Unrecognized field \"<img src=x onerror=\"alert('Bo0oq')\"/>\ ...

But it would need to look like here: https://medium.com/@raia39499/how-i-exploit-cve-2021-20323-33d2f8d6826c

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggood first issueGood for newcomerstemplateIssue in BCheck template

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions