Skip to content

SAML javascript protocol mapper: Uploading of scripts through admin console

Low
abstractj published GHSA-wf7g-7h6h-678v Sep 22, 2022

Package

maven org.keycloak (Maven)

Affected versions

< 19.0.2

Patched versions

19.0.2

Description

An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled

Severity

Low

CVE ID

CVE-2022-2668

Weaknesses