GHSA-wf7g-7h6h-678v
GitHub Security Advisory
Keycloak SAML javascript protocol mapper: Uploading of scripts through admin console
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
An issue was discovered in Keycloak allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the `UPLOAD_SCRIPTS` feature is disabled
Affected Packages
Maven
org.keycloak:keycloak-parent
Affected versions:
0
(fixed in 19.0.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 23, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.