You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Keycloak SAML javascript protocol mapper: Uploading of scripts through admin console
High severity
GitHub Reviewed
Published
Sep 22, 2022
in
keycloak/keycloak
•
Updated Jan 8, 2023
An issue was discovered in Keycloak allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
An issue was discovered in Keycloak allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the
UPLOAD_SCRIPTS
feature is disabledReferences