CVE Vulnerabilities

CVE-2022-2668

Published: Aug 05, 2022 | Modified: Aug 11, 2022
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled

Affected Software

Name Vendor Start Version End Version
Keycloak Redhat 18.0.0 (including) 18.0.0 (including)
Single_sign-on Redhat 7.0 (including) 7.0 (including)

References