CVE-2022-1466

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:40

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2050228 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2050228 - Issue Tracking, Vendor Advisory
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt - Exploit, Third Party Advisory () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt - Exploit, Third Party Advisory
References () https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076 - Exploit, Third Party Advisory () https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076 - Exploit, Third Party Advisory

Information

Published : 2022-04-26 19:15

Updated : 2024-11-21 06:40


NVD link : CVE-2022-1466

Mitre link : CVE-2022-1466

CVE.ORG link : CVE-2022-1466


JSON object : View

Products Affected

redhat

  • keycloak
  • single_sign-on
CWE
CWE-863

Incorrect Authorization