Security Flaw in Keycloak Admin Console Affects User Permissions
CVE-2019-10170
6.6MEDIUM
What is CVE-2019-10170?
A security flaw in the Keycloak admin console allows authenticated users with realm management permissions to set a malicious script through the policy interface. This opens the door for attackers to execute arbitrary code with the application user's privileges, potentially leading to unauthorized access and data breaches.
Affected Version(s)
keycloak 8.0.0
