CVE Vulnerabilities

CVE-2022-2668

Published: Aug 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled

Affected Software

NameVendorStart VersionEnd Version
KeycloakRedhat18.0.0 (including)18.0.0 (including)
Single_sign-onRedhat7.0 (including)7.0 (including)
Red Hat Single Sign-On 7RedHatkeycloak-saml-core*
Red Hat Single Sign-On 7.5 for RHEL 7RedHatrh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el7sso*
Red Hat Single Sign-On 7.5 for RHEL 8RedHatrh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el8sso*
Red Hat Single Sign-On 7.6.1RedHatkeycloak-saml-core*
Red Hat Single Sign-On 7.6 for RHEL 7RedHatrh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el7sso*
Red Hat Single Sign-On 7.6 for RHEL 8RedHatrh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el8sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-0:1-5.el9sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-javapackages-tools-0:6.0.0-7.el9sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el9sso*

References