A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3346 A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
Github GHSA Github GHSA GHSA-9c24-43p5-fv82 Keycloak code execution via UMA policy abuse
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T22:10:10.032Z

Reserved: 2019-03-27T00:00:00

Link: CVE-2019-10169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-08T14:15:11.500

Modified: 2024-11-21T04:18:34.090

Link: CVE-2019-10169

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-04-30T00:00:00Z

Links: CVE-2019-10169 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses