Burp Suite User Forum

Create new post

SQL injection false positives with Keycloak SSO?

LD | Last updated: Apr 05, 2023 02:40PM UTC

Testing with the latest release of BurpSuite Pro against an instance of Keycloak 16, I get a number of reports of "SQL injection" issues. However, when looking at the response HTML I see no indication of any errors, which is simply the normal SSO login page. Checking application logs, I'm seeing no indications of errors as well. Exporting the requests as curl commands yield identical results: calls to the APIs, which get 302 redirected to the login page. My only guess is that an inline SVG in the response might be tripping up the scanner. I can supply both sanitized request and response documents to show the test/results, but I don't see a way to directly attach files.

LD | Last updated: Apr 05, 2023 06:11PM UTC

As an update, we've deployed a version that does not contain the inline SVG in the login page, but we're seeing identical results. It's perplexing.

Ben, PortSwigger Agent | Last updated: Apr 06, 2023 07:59AM UTC

Hi, Are you able to send us an email at support@portswigger.net and include the request and response (with as much unsanitized detail as possible) so that we can take a look at this for you?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.