Описание
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Ссылки
- Issue TrackingVendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Issue TrackingVendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 17.0.1 (исключая)
Одно из
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00158
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 6.5
redhat
около 4 лет назад
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
EPSS
Процентиль: 37%
0.00158
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-863
CWE-863