CVE-2022-1245
published 2022-07-08CVE-2022-1245: A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.30%
67.3th percentile
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_edge | — | — |
| redhat | keycloak | < 18.0.0 | 18.0.0 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
vendor_msrc9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC
vendor_msrc·2022-07-12·CVSS 8.8
CVE-2022-2294 [HIGH] Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC
Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
103.0.1264.49
7/6/2022
103.0.5060.114
Extended Stable: 102.0.1245.56
7/6/2022
102.0.5005.148
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longe
Microsoft
Chromium: CVE-2022-2007 Use after free in WebGPU
vendor_msrc·2022-06-14·CVSS 8.8
CVE-2022-2007 [HIGH] Chromium: CVE-2022-2007 Use after free in WebGPU
Chromium: CVE-2022-2007 Use after free in WebGPU
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.41
6/13/2022
102.0.5005.115
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In yo
Microsoft
Chromium: CVE-2022-2010 Out of bounds read in compositing
vendor_msrc·2022-06-14·CVSS 9.3
CVE-2022-2010 [CRITICAL] Chromium: CVE-2022-2010 Out of bounds read in compositing
Chromium: CVE-2022-2010 Out of bounds read in compositing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.41
6/13/2022
102.0.5005.115
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browse
Microsoft
Chromium: CVE-2022-2011 Use after free in ANGLE
vendor_msrc·2022-06-14·CVSS 8.8
CVE-2022-2011 [HIGH] Chromium: CVE-2022-2011 Use after free in ANGLE
Chromium: CVE-2022-2011 Use after free in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.41
6/13/2022
102.0.5005.115
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In you
Microsoft
Chromium: CVE-2022-2008 Out of bounds memory access in WebGL
vendor_msrc·2022-06-14·CVSS 8.8
CVE-2022-2008 [HIGH] Chromium: CVE-2022-2008 Out of bounds memory access in WebGL
Chromium: CVE-2022-2008 Out of bounds memory access in WebGL
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.41
6/13/2022
102.0.5005.115
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the bro
Microsoft
Chromium: CVE-2022-1854 Use after free in ANGLE
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1854 [HIGH] Chromium: CVE-2022-1854 Use after free in ANGLE
Chromium: CVE-2022-1854 Use after free in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your
Microsoft
Chromium: CVE-2022-1862 Inappropriate implementation in Extensions
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-1862 [MEDIUM] Chromium: CVE-2022-1862 Inappropriate implementation in Extensions
Chromium: CVE-2022-1862 Inappropriate implementation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of th
Microsoft
Chromium: CVE-2022-1876 Heap buffer overflow in DevTools
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1876 [HIGH] Chromium: CVE-2022-1876 Heap buffer overflow in DevTools
Chromium: CVE-2022-1876 Heap buffer overflow in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2022-1864 Use after free in WebApp Installs
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1864 [HIGH] Chromium: CVE-2022-1864 Use after free in WebApp Installs
Chromium: CVE-2022-1864 Use after free in WebApp Installs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser
Microsoft
Chromium: CVE-2022-1871 Insufficient policy enforcement in File System API
vendor_msrc·2022-05-10·CVSS 4.3
CVE-2022-1871 [MEDIUM] Chromium: CVE-2022-1871 Insufficient policy enforcement in File System API
Chromium: CVE-2022-1871 Insufficient policy enforcement in File System API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the versi
Microsoft
Chromium: CVE-2022-1855 Use after free in Messaging
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1855 [HIGH] Chromium: CVE-2022-1855 Use after free in Messaging
Chromium: CVE-2022-1855 Use after free in Messaging
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2022-1869 Type Confusion in V8
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-1869 [MEDIUM] Chromium: CVE-2022-1869 Type Confusion in V8
Chromium: CVE-2022-1869 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Mi
Microsoft
Chromium: CVE-2022-1874 Insufficient policy enforcement in Safe Browsing
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1874 [HIGH] Chromium: CVE-2022-1874 Insufficient policy enforcement in Safe Browsing
Chromium: CVE-2022-1874 Insufficient policy enforcement in Safe Browsing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Microsoft
Chromium: CVE-2022-1858 Out of bounds read in DevTools
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-1858 [MEDIUM] Chromium: CVE-2022-1858 Out of bounds read in DevTools
Chromium: CVE-2022-1858 Out of bounds read in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2022-1863 Use after free in Tab Groups
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1863 [HIGH] Chromium: CVE-2022-1863 Use after free in Tab Groups
Chromium: CVE-2022-1863 Use after free in Tab Groups
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2022-1870 Use after free in App Service
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1870 [HIGH] Chromium: CVE-2022-1870 Use after free in App Service
Chromium: CVE-2022-1870 Use after free in App Service
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
I
Microsoft
Chromium: CVE-2022-1875 Inappropriate implementation in PDF
vendor_msrc·2022-05-10·CVSS 4.3
CVE-2022-1875 [MEDIUM] Chromium: CVE-2022-1875 Inappropriate implementation in PDF
Chromium: CVE-2022-1875 Inappropriate implementation in PDF
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brows
Microsoft
Chromium: CVE-2022-1867 Insufficient validation of untrusted input in Data Transfer
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-1867 [MEDIUM] Chromium: CVE-2022-1867 Insufficient validation of untrusted input in Data Transfer
Chromium: CVE-2022-1867 Insufficient validation of untrusted input in Data Transfer
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see
Microsoft
Chromium: CVE-2022-1868 Inappropriate implementation in Extensions API
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-1868 [MEDIUM] Chromium: CVE-2022-1868 Inappropriate implementation in Extensions API
Chromium: CVE-2022-1868 Inappropriate implementation in Extensions API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version o
Microsoft
Chromium: CVE-2022-1873 Insufficient policy enforcement in COOP
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-1873 [MEDIUM] Chromium: CVE-2022-1873 Insufficient policy enforcement in COOP
Chromium: CVE-2022-1873 Insufficient policy enforcement in COOP
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the b
Microsoft
Microsoft Edge (Chromium-based) Spoofing Vulnerability
vendor_msrc·2022-05-10·CVSS 4.3
CVE-2022-26905 [MEDIUM] Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user have multiple browser instances open of the affected version of Microsoft Edge (Chromium-based), one of which is a specially crafted website hosted by the attacker. The user would need to access the URL of the malicious website and then click a popup displayed on that site.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for t
Microsoft
Chromium: CVE-2022-1865 Use after free in Bookmarks
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1865 [HIGH] Chromium: CVE-2022-1865 Use after free in Bookmarks
Chromium: CVE-2022-1865 Use after free in Bookmarks
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2022-1859 Use after free in Performance Manager
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1859 [HIGH] Chromium: CVE-2022-1859 Use after free in Performance Manager
Chromium: CVE-2022-1859 Use after free in Performance Manager
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the bro
Microsoft
Chromium: CVE-2022-1857 Insufficient policy enforcement in File System API
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1857 [HIGH] Chromium: CVE-2022-1857 Insufficient policy enforcement in File System API
Chromium: CVE-2022-1857 Insufficient policy enforcement in File System API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the versi
Microsoft
Chromium: CVE-2022-1856 Use after free in User Education
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1856 [HIGH] Chromium: CVE-2022-1856 Use after free in User Education
Chromium: CVE-2022-1856 Use after free in User Education
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2022-1853 Use after free in Indexed DB
vendor_msrc·2022-05-10·CVSS 9.6
CVE-2022-1853 [CRITICAL] Chromium: CVE-2022-1853 Use after free in Indexed DB
Chromium: CVE-2022-1853 Use after free in Indexed DB
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2022-1872 Insufficient policy enforcement in Extensions API
vendor_msrc·2022-05-10·CVSS 4.3
CVE-2022-1872 [MEDIUM] Chromium: CVE-2022-1872 Insufficient policy enforcement in Extensions API
Chromium: CVE-2022-1872 Insufficient policy enforcement in Extensions API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.30
5/31/2022
102.0.5005.61
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the versio
Red Hat
keycloak: Privilege escalation vulnerability on Token Exchange
vendor_redhat·2022-04-19·CVSS 9.8
CVE-2022-1245 [CRITICAL] CWE-639 keycloak: Privilege escalation vulnerability on Token Exchange
keycloak: Privilege escalation vulnerability on Token Exchange
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
Statement: The token exchange feature is currently in technology preview and is not fully suppor
GHSA
Keycloak vulnerable to privilege escalation on Token Exchange feature
ghsa·2022-04-26
CVE-2022-1245 [CRITICAL] CWE-639 Keycloak vulnerable to privilege escalation on Token Exchange feature
Keycloak vulnerable to privilege escalation on Token Exchange feature
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
OSV
Keycloak vulnerable to privilege escalation on Token Exchange feature
osv·2022-04-26
CVE-2022-1245 [CRITICAL] Keycloak vulnerable to privilege escalation on Token Exchange feature
Keycloak vulnerable to privilege escalation on Token Exchange feature
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-08
Published