Privilege Defined With Unsafe Actions in Keycloak
High severity
GitHub Reviewed
Published
Oct 21, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 8, 2020
Reviewed
Oct 20, 2021
Published to the GitHub Advisory Database
Oct 21, 2021
Last updated
Feb 1, 2023
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.
References