Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1466

Опубликовано: 10 янв. 2022
Источник: redhat
CVSS3: 6.5

Описание

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

A flaw was found in Keycloak. The Red Hat Single Sign-On allowed authed users to perform actions outside their permissions. This flaw makes adding users to the master realm possible even though no respective permission was granted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat Integration Camel K 1keycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected
Red Hat support for Spring BootkeycloakNot affected
RHSSO 7.5.1FixedRHSA-2022:044907.02.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863->CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2050228keycloak: Improper authorization for master realm

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

CVSS3: 6.5
github
почти 4 года назад

Improper authorization in Keycloak

6.5 Medium

CVSS3