CVE-2022-1466Incorrect Authorization in Redhat Single Sign-on

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 63.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 26
Latest updateApr 27

Description

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDredhat/keycloak< 17.0.1

🔴Vulnerability Details

3
GHSA
Improper authorization in Keycloak2022-04-27
OSV
Improper authorization in Keycloak2022-04-27
CVEList
CVE-2022-1466: Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform2022-04-26

📋Vendor Advisories

1
Red Hat
keycloak: Improper authorization for master realm2022-01-10
CVE-2022-1466 — Incorrect Authorization in Redhat | cvebase