Описание
No description is available for this CVE.
Отчет
This issue was rated MODERATE. A privilege escalation flaw exists in Keycloak where an administrator with manage-clients permission can escalate privileges if "Admin Permissions" are enabled at the realm level.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-services | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Fix deferred | ||
| Red Hat Single Sign-On 7 | keycloak-services | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2442277keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission
6.5 Medium
CVSS3
Связанные уязвимости
6.5 Medium
CVSS3