mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-21 04:46:48 +02:00
782 B
782 B
CVE-2019-10169
Description
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
POC
Reference
No PoCs from references.