Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c24-43p5-fv82

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Keycloak code execution via UMA policy abuse

A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.

Пакеты

Наименование

org.keycloak:keycloak-authz-client

maven
Затронутые версииВерсия исправления

< 8.0.0

8.0.0

EPSS

Процентиль: 69%
0.00608
Низкий

7.2 High

CVSS3

Дефекты

CWE-267

Связанные уязвимости

CVSS3: 6.6
redhat
почти 6 лет назад

A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.

CVSS3: 6.6
nvd
больше 5 лет назад

A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.

CVSS3: 6.6
debian
больше 5 лет назад

A flaw was found in Keycloak\u2019s user-managed access interface, whe ...

EPSS

Процентиль: 69%
0.00608
Низкий

7.2 High

CVSS3

Дефекты

CWE-267