First published: Thu Aug 04 2022(Updated: )
A flaw was found in keycloak. The vulnerability allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/keycloak | <19.0.2 | 19.0.2 |
redhat/rh-sso7-keycloak | <0:15.0.8-1.redhat_00001.1.el7 | 0:15.0.8-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:15.0.8-1.redhat_00001.1.el8 | 0:15.0.8-1.redhat_00001.1.el8 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el7 | 0:18.0.3-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el8 | 0:18.0.3-1.redhat_00001.1.el8 |
redhat/rh-sso7 | <0:1-5.el9 | 0:1-5.el9 |
redhat/rh-sso7-javapackages-tools | <0:6.0.0-7.el9 | 0:6.0.0-7.el9 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el9 | 0:18.0.3-1.redhat_00001.1.el9 |
Redhat Keycloak | =18.0.0 | |
Redhat Single Sign-on | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-2668 is a vulnerability found in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper, even if the UPLOAD_SCRIPTS feature is disabled.
Keycloak versions up to, but excluding, 19.0.2, rh-sso7-keycloak versions up to, but excluding, 0:15.0.8-1.redhat_00001.1.el7, rh-sso7-keycloak versions up to, but excluding, 0:15.0.8-1.redhat_00001.1.el8, rh-sso7-keycloak versions up to, but excluding, 0:18.0.3-1.redhat_00001.1.el7, rh-sso7-keycloak versions up to, but excluding, 0:18.0.3-1.redhat_00001.1.el8, rh-sso7, rh-sso7-javapackages-tools versions up to, but excluding, 0:1-5.el9, and rh-sso7-keycloak versions up to, but excluding, 0:18.0.3-1.redhat_00001.1.el9 are affected by CVE-2022-2668.
The severity of CVE-2022-2668 is high with a CVSS score of 7.2.
To fix CVE-2022-2668, you should update your Keycloak, rh-sso7-keycloak, rh-sso7, rh-sso7-javapackages-tools to versions 19.0.2, 0:15.0.8-1.redhat_00001.1.el7, 0:15.0.8-1.redhat_00001.1.el8, 0:18.0.3-1.redhat_00001.1.el7, 0:18.0.3-1.redhat_00001.1.el8, 0:1-5.el9, and 0:18.0.3-1.redhat_00001.1.el9 respectively, which have the necessary remediation for this vulnerability.
The Common Weakness Enumeration (CWE) of CVE-2022-2668 is CWE-440.