CVE-2021-4133
HIGH8.8EPSS 0.43%Improper Authorization in Keycloak
發布日:2022/1/6修改日:2026/3/13
描述
A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.
受影響套件(1)
- Maven/org.keycloak:keycloak-servicesfrom 0, < 15.1.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-4133
- PATCHhttps://github.com/keycloak/keycloak
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=2033602
- WEBhttps://github.com/keycloak/keycloak/issues/9247
- WEBhttps://github.com/keycloak/keycloak/security/advisories/GHSA-83x4-9cwr-5487
- WEBhttps://www.oracle.com/security-alerts/cpuapr2022.html