CVE-2022-2668
HIGHKeycloak < 19.0.2 - Arbitrary JavaScript Upload via SAML Protocol Mapper
Title source: llmDescription
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
References (1)
Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://access.redhat.com/security/cve/CVE-2022-2668
Scores
CVSS v3
7.2
EPSS
0.0047
EPSS Percentile
64.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (3)
org.keycloak/keycloak-parent
0 - 19.0.2Maven
redhat/keycloak
18.0.0
redhat/single_sign-on
7.0
Published
Aug 05, 2022
Tracked Since
Feb 18, 2026