CVE-2021-4133
published 2022-01-25CVE-2021-4133: A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.35%
68.3th percentile
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | — | — |
| redhat | keycloak | >= 12.0.0 < 15.1.1 | 15.1.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authorization in Keycloak
osv·2022-01-06
CVE-2021-4133 [HIGH] Improper Authorization in Keycloak
Improper Authorization in Keycloak
A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.
GHSA
Improper Authorization in Keycloak
ghsa·2022-01-06
CVE-2021-4133 [HIGH] CWE-863 Improper Authorization in Keycloak
Improper Authorization in Keycloak
A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.
Red Hat
Keycloak: Incorrect authorization allows unpriviledged users to create other users
vendor_redhat·2021-12-16·CVSS 8.8
CVE-2021-4133 [HIGH] CWE-863 Keycloak: Incorrect authorization allows unpriviledged users to create other users
Keycloak: Incorrect authorization allows unpriviledged users to create other users
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
A flaw was found in Keycloak version from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
Statement: This flaw affects only Red Hat Single Sign-on 7.5.0. Red Hat Single Sign-on 7.4.x releases are NOT affected. Fix is available for download from customer portal which can be applied on RH-SSO 7.5.0
Mitigation: Access to the use
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2033602https://github.com/keycloak/keycloak/issues/9247https://github.com/keycloak/keycloak/security/advisories/GHSA-83x4-9cwr-5487https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2033602https://github.com/keycloak/keycloak/issues/9247https://github.com/keycloak/keycloak/security/advisories/GHSA-83x4-9cwr-5487https://www.oracle.com/security-alerts/cpuapr2022.html
2022-01-25
Published