GHSA-f32v-vf79-p29q
Dashboard / Vulnerabilities / GHSA-f32v-vf79-p29q
Summary: Improper authorization in Keycloak
Details: Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-1466, https://bugzilla.redhat.com/show_bug.cgi?id=2050228, https://github.com/keycloak/keycloak, https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt, https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076
Affected packages
Package
Name: org.keycloak:keycloak-core
Purl: pkg:maven/org.keycloak/keycloak-core
Affected ranges
Type: ECOSYSTEM
Events:
