Description
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1660 | A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services. |
Github GHSA |
GHSA-75p6-52g3-rqc8 | Keycloak vulnerable to privilege escalation on Token Exchange feature |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-02T23:55:24.704Z
Reserved: 2022-04-05T00:00:00.000Z
Link: CVE-2022-1245
No data.
Status : Modified
Published: 2022-07-08T00:15:07.937
Modified: 2024-11-21T06:40:20.053
Link: CVE-2022-1245
OpenCVE Enrichment
No data.
EUVD
Github GHSA