OSV 1.4.0 · github-reviewed · 修改于 2021-10-20 23:06
发布时间
2021-10-22 01:46
GitHub 审查时间
2021-10-20 23:06
NVD 发布时间
2020-05-08 22:15
源文件
advisories/github-reviewed/2021/10/GHSA-7m27-3587-83xf/GHSA-7m27-3587-83xf.json
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.