Back to search
CVE-2022-1245
Published: Jul 7, 2022
Modified: Aug 2, 2024
PUBLISHED
Description
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
| Vendor | Product | Versions |
|---|---|---|
n/a | keycloak | affected keycloak versions prior to 18.0.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now