Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f32v-vf79-p29q

Опубликовано: 27 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Improper authorization in Keycloak

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 17.0.1

17.0.1

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
redhat
около 4 лет назад

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

CVSS3: 6.5
nvd
почти 4 года назад

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863