CVE-2022-1245: Critical severity red hat keycloak vulnerability
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the clientid of the target. This could allow a client to gain unauthorized access to additional services.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1245?
CVE-2022-1245 is a privilege escalation vulnerability found in the token exchange feature of Keycloak.
How severe is CVE-2022-1245?
CVE-2022-1245 has a severity score of 9.8, which is considered critical.
Which software versions are affected by CVE-2022-1245?
The affected software version is Red Hat Keycloak up to version 18.0.0.
What is the impact of CVE-2022-1245?
The vulnerability allows a client application to gain unauthorized access to arbitrary client accounts.
Is there a fix for CVE-2022-1245?
Patch and upgrade to a fixed version of Red Hat Keycloak to mitigate the vulnerability.