Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33546
HistoryJan 07, 2022 - 6:42 a.m.

Authorization Bypass

2022-01-0706:42:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
keycloak
authorization bypass
user permissions
rest api
software

EPSS

0.005

Percentile

76.0%

keycloak-services is vulnerable to authorization bypass. The library does not properly validate the existing user permissions, allowing an authorized attacker to create new default user accounts via the administrative REST API.

EPSS

0.005

Percentile

76.0%