CVE-2022-1466

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-04-26 19:15

Updated : 2024-02-28 19:09


NVD link : CVE-2022-1466

Mitre link : CVE-2022-1466

CVE.ORG link : CVE-2022-1466


JSON object : View

Products Affected

redhat

  • single_sign-on
  • keycloak
CWE
CWE-863

Incorrect Authorization