GHSA-q2gp-gph3-88x9
Dashboard / Vulnerabilities / GHSA-q2gp-gph3-88x9
GHSA-q2gp-gph3-88x9
Summary: Keycloak allows arbitrary Javascript to be uploaded for SAML protocol mapper even if UPLOAD_SCRIPTS feature disabled
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of [GHSA-wf7g-7h6h-678v](https://github.com/advisories/GHSA-wf7g-7h6h-678v). This link is maintained to preserve external references. ## Original Description An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-2668, https://access.redhat.com/security/cve/CVE-2022-2668, https://bugzilla.redhat.com/show_bug.cgi?id=2115392, https://github.com/keycloak/keycloak
Affected packages
Package
Name: org.keycloak:keycloak-saml-core
Purl: pkg:maven/org.keycloak/keycloak-saml-core
Affected ranges
Type: ECOSYSTEM
Events:
