CVE-2022-1466

MEDIUM

Redhat Keycloak < 17.0.1 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

References (3)

Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2050228

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-863
Status published
Products (3)
org.keycloak/keycloak-core 0 - 17.0.1Maven
redhat/keycloak < 17.0.1
redhat/single_sign-on 7.5.0
Published Apr 26, 2022
Tracked Since Feb 18, 2026