First published: Thu Jul 07 2022(Updated: )
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Keycloak | <18.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1245 is a privilege escalation vulnerability found in the token exchange feature of Keycloak.
CVE-2022-1245 has a severity score of 9.8, which is considered critical.
The affected software version is Red Hat Keycloak up to version 18.0.0.
The vulnerability allows a client application to gain unauthorized access to arbitrary client accounts.
Patch and upgrade to a fixed version of Red Hat Keycloak to mitigate the vulnerability.