mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 21:18:06 +02:00
18 lines
782 B
Markdown
18 lines
782 B
Markdown
### [CVE-2019-10169](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10169)
|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
No PoCs from references.
|
||
|
||
#### Github
|
||
- https://github.com/ARPSyndicate/cve-scores
|
||
|