Loading HuntDB...

GHSA-wf7g-7h6h-678v

GitHub Security Advisory

Keycloak SAML javascript protocol mapper: Uploading of scripts through admin console

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

An issue was discovered in Keycloak allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the `UPLOAD_SCRIPTS` feature is disabled

Affected Packages

Maven org.keycloak:keycloak-parent
Affected versions: 0 (fixed in 19.0.2)

Related CVEs

Key Information

GHSA ID
GHSA-wf7g-7h6h-678v
Published
September 23, 2022 4:32 PM
Last Modified
September 23, 2022 4:32 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.keycloak:keycloak-parent
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 23, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.