GHSA-83x4-9cwr-5487
Dashboard / Vulnerabilities / GHSA-83x4-9cwr-5487
Summary: Improper Authorization in Keycloak
Details: A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.
References: https://github.com/keycloak/keycloak/security/advisories/GHSA-83x4-9cwr-5487, https://nvd.nist.gov/vuln/detail/CVE-2021-4133, https://github.com/keycloak/keycloak/issues/9247, https://bugzilla.redhat.com/show_bug.cgi?id=2033602, https://github.com/keycloak/keycloak, https://www.oracle.com/security-alerts/cpuapr2022.html
Affected packages
Package
Name: org.keycloak:keycloak-services
Purl: pkg:maven/org.keycloak/keycloak-services
Affected ranges
Type: ECOSYSTEM
Events:
