Junglewise Threat Intelligence

Keycloak allows arbitrary Javascript to be uploaded for SAML protocol mapper even if UPLOAD_SCRIPTS feature disabled

Severity: low · CVSS 3.1 · Published 2022-08-06

Technologies: org.keycloak:keycloak-saml-core (Maven). Vendors: Maven.

Executive brief

Keycloak allows arbitrary Javascript to be uploaded for SAML protocol mapper even if UPLOAD_SCRIPTS feature disabled

Affected products

  • Maven org.keycloak:keycloak-saml-core

Related threats