Lucene search

K
osvGoogleOSV:GHSA-83X4-9CWR-5487
HistoryJan 06, 2022 - 6:32 p.m.

Improper Authorization in Keycloak

2022-01-0618:32:58
Google
osv.dev
19
keycloak
authorization
flaw
user accounts
rest api
user registration

EPSS

0.005

Percentile

76.0%

A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.

EPSS

0.005

Percentile

76.0%