A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.
2020-05-08T14:15:11.577
2024-11-21T04:18:34.220
Modified
CVSSv3.1: 6.6 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4