CVE ID: CVE-2025-10044 Severity: Moderate CVSS v3 Base Score: 4.3 Description: A flaw was found in Keystone's account console and other pages accepting arbitrary input in the HTML element property values within an embedded configuration. When HTML encoding failed, cross-site scripting (XSS) could occur. Mitigation: Mitigation for this issue is either not available or the currently available solutions do not meet the Red Hat Product Security criteria considering user impact and deployment applicability. Additional Information: - Help for [CWE-79] Cross-site Scripting description injection on web pages. - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). Affected Packages and Issued Red Hat Security Errata: No affected packages listed. Common Vulnerability Scoring System (CVSS) Score Details: - CVSS v3 Base Score: 4.3 - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Confidentiality Impact: None - Integrity Impact: Low - Availability Impact: None Understanding the Weakness (CWE): - CWE-79: Access Control, Confidentiality - Technical Impact: Execute Unauthorized Code or Commands