PT-2022-13909 · Red Hat · Red Hat Single Sign-On+1

Christian Dölling

·

Published

2022-04-26

·

Updated

2022-05-06

·

CVE-2022-1466

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Single Sign-On (affected versions not specified)
Description The issue is related to improper authorization, allowing users to perform actions they should not be allowed to. Specifically, it was possible to add users to the master realm without having the respective permission granted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1466
GHSA-F32V-VF79-P29Q

Affected Products

Keycloak
Red Hat Single Sign-On