CVE-2021-4133

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 6.5 (Medium)
65% Progress
EPSS 0.24 % (62th)
0.24% Progress
Affected Products 1
Advisories 1

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

Weaknesses
CWE-863
Incorrect Authorization
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-01-25 20:15:08
(2 years ago)
Updated Date
2022-09-03 03:33:21
(2 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Keycloak from 12.0.0 version and prior 15.1.1 version cpe:2.3:a:redhat:keycloak >= 12.0.0 < 15.1.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...