PT-2022-18005 · Red Hat · Keycloak

Marek Posolda

·

Published

2022-08-05

·

Updated

2022-09-23

·

CVE-2022-2668

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD SCRIPTS feature is disabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-2668
GHSA-Q2GP-GPH3-88X9
GHSA-WF7G-7H6H-678V
RHSA-2022:6782
RHSA-2022:6783
RHSA-2022:7409
RHSA-2022:7410
RHSA-2022:7411

Affected Products

Keycloak