Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1245

Опубликовано: 19 апр. 2022
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

Отчет

The token exchange feature is currently in technology preview and is not fully supported. Please see the documentation for more information on this feature: https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.5/html/securing_applications_and_services_guide/token-exchange

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2071036keycloak: Privilege escalation vulnerability on Token Exchange

EPSS

Процентиль: 61%
0.00418
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

CVSS3: 9.8
debian
больше 3 лет назад

A privilege escalation flaw was found in the token exchange feature of ...

CVSS3: 9.8
github
почти 4 года назад

Keycloak vulnerable to privilege escalation on Token Exchange feature

EPSS

Процентиль: 61%
0.00418
Низкий

8 High

CVSS3