Description
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2173 | A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user. |
Github GHSA |
GHSA-7m27-3587-83xf | Privilege Defined With Unsafe Actions in Keycloak |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:09.965Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10170
No data.
Status : Modified
Published: 2020-05-08T14:15:11.577
Modified: 2024-11-21T04:18:34.220
Link: CVE-2019-10170
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA