QID 980341
QID 980341: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-7m27-3587-83xf)
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7m27-3587-83xf for updates pertaining to this vulnerability.
Vendor References
- GHSA-7m27-3587-83xf -
github.com/advisories/GHSA-7m27-3587-83xf
CVEs related to QID 980341
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7m27-3587-83xf | org.keycloak:keycloak-core |
|