Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75p6-52g3-rqc8

Опубликовано: 26 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Keycloak vulnerable to privilege escalation on Token Exchange feature

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 18.0.0

18.0.0

EPSS

Процентиль: 61%
0.00418
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-639
CWE-862
CWE-863

Связанные уязвимости

CVSS3: 8
redhat
почти 4 года назад

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

CVSS3: 9.8
nvd
больше 3 лет назад

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

CVSS3: 9.8
debian
больше 3 лет назад

A privilege escalation flaw was found in the token exchange feature of ...

EPSS

Процентиль: 61%
0.00418
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-639
CWE-862
CWE-863