Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9cj-v55f-8x26

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Authentication Bypass in keycloak

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 12.0.0

12.0.0

EPSS

Процентиль: 38%
0.00166
Низкий

8.8 High

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 4.2
redhat
около 5 лет назад

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

CVSS3: 4.2
nvd
больше 4 лет назад

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

CVSS3: 4.2
debian
больше 4 лет назад

A flaw was found in Keycloak before version 12.0.0 where it is possibl ...

EPSS

Процентиль: 38%
0.00166
Низкий

8.8 High

CVSS3

Дефекты

CWE-250