CVE-2022-1245

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 0.24 % (63th)
0.24% Progress
Affected Products 1
Advisories 1

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

Weaknesses
CWE-639
Authorization Bypass Through User-Controlled Key
CWE-862
Missing Authorization
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-07-08 00:15:07
(2 years ago)
Updated Date
2023-11-07 03:41:50
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Keycloak prior 18.0.0 version cpe:2.3:a:redhat:keycloak < 18.0.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...