CVE Database
/

CVE-2022-1245

Back to search

CVE-2022-1245

Published: Jul 7, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

VendorProductVersions

n/a

keycloak

affected
keycloak versions prior to 18.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now