Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4133

Опубликовано: 16 дек. 2021
Источник: redhat
CVSS3: 8.3

Описание

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

A flaw was found in Keycloak version from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

Отчет

This flaw affects only Red Hat Single Sign-on 7.5.0. Red Hat Single Sign-on 7.4.x releases are NOT affected. Fix is available for download from customer portal which can be applied on RH-SSO 7.5.0

Меры по смягчению последствий

Access to the user-creation functionality in the REST endpoint can be deactivated using CLI commands in undertow. run: bin/jboss-cli.sh --connect /subsystem=undertow/configuration=filter/expression-filter=keycloakPathOverrideUsersCreateEndpoint:add(
expression="(regex('^/auth/admin/realms/(.*)/users$') and method(POST))-> response-code(400)"
) /subsystem=undertow/server=default-server/host=default-host/filter-ref=keycloakPathOverrideUsersCreateEndpoint:add()

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat A-MQ Onlinekeycloak-servicesNot affected
Red Hat Single Sign-On 7.5 for RHEL 7rh-sso7-keycloakFixedRHSA-2021:521820.12.2021
Red Hat Single Sign-On 7.5 for RHEL 7rh-sso7-keycloakFixedRHSA-2022:015117.01.2022
Red Hat Single Sign-On 7.5 for RHEL 8rh-sso7-keycloakFixedRHSA-2021:521920.12.2021
Red Hat Single Sign-On 7.5 for RHEL 8rh-sso7-keycloakFixedRHSA-2022:015217.01.2022
RHEL-8 based Middleware Containersrh-sso-7/sso75-openshift-rhel8FixedRHSA-2022:001504.01.2022
RHEL-8 based Middleware Containersrh-sso-7/sso7-rhel8-operator-bundleFixedRHSA-2022:001504.01.2022
RHEL-8 based Middleware Containersrh-sso-7/sso7-rhel8-operator-bundleFixedRHSA-2022:003405.01.2022
RHEL-8 based Middleware Containersrh-sso-7/sso75-openshift-rhel8FixedRHSA-2022:016418.01.2022
RHSSO 7.5.1keycloak-servicesFixedRHSA-2022:015517.01.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2033602Keycloak: Incorrect authorization allows unpriviledged users to create other users

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

CVSS3: 8.8
debian
около 4 лет назад

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 ...

CVSS3: 8.8
github
около 4 лет назад

Improper Authorization in Keycloak

8.3 High

CVSS3