CVE-2022-1245
CVSS v3.1
9.8 (Critical)
CVSS v2.0
7.5 (High)
EPSS
0.24 % (63th)
Affected Products
1
Advisories
1
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
- CVE Status
- PUBLISHED
- CNA
- Red Hat, Inc.
- Published Date
-
2022-07-08 00:15:07
(2 years ago) - Updated Date
-
2023-11-07 03:41:50
(10 months ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...