Keycloak code execution via UMA policy abuse
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2024
Description
Published by the National Vulnerability Database
May 8, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Apr 23, 2024
Last updated
Apr 23, 2024
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
References