CVE-2022-1466
26.04.2022, 19:15
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | keycloak | 𝑥 < 17.0.1 |
| redhat | single_sign-on | 7.5.0 |
𝑥
= Vulnerable software versions
References