{"id":"CVE-2019-10170","aliases":["GHSA-7m27-3587-83xf"],"url":"https://o3.security/vulnerability/CVE-2019-10170","summary":"Privilege Defined With Unsafe Actions in Keycloak","details":"A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.","published":"2020-05-08T14:15:11.577Z","modified":"2026-08-07T14:59:50.855309Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-core","fixedVersion":"8.0.0"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10170"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:59:50.855309Z"}}