Open mend-bolt-for-github[bot] opened 2 years ago
Keycloak SSO
Library home page: http://keycloak.org
Path to dependency file: /pom.xml
Path to vulnerable library: /canner/.m2/repository/org/keycloak/keycloak-core/11.0.0-alfresco-001/keycloak-core-11.0.0-alfresco-001.jar
Dependency Hierarchy: - :x: **keycloak-core-11.0.0-alfresco-001.jar** (Vulnerable Library)
Found in base branch: master
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Publish Date: 2022-04-26
URL: CVE-2022-1466
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: None
Type: Upgrade version
Origin: https://github.com/advisories/GHSA-f32v-vf79-p29q
Release Date: 2022-04-26
Fix Resolution: 17.0.1
Step up your Open Source Security Game with Mend here
CVE-2022-1466 - Medium Severity Vulnerability
Vulnerable Library - keycloak-core-11.0.0-alfresco-001.jar
Keycloak SSO
Library home page: http://keycloak.org
Path to dependency file: /pom.xml
Path to vulnerable library: /canner/.m2/repository/org/keycloak/keycloak-core/11.0.0-alfresco-001/keycloak-core-11.0.0-alfresco-001.jar
Dependency Hierarchy: - :x: **keycloak-core-11.0.0-alfresco-001.jar** (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Publish Date: 2022-04-26
URL: CVE-2022-1466
CVSS 3 Score Details (6.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://github.com/advisories/GHSA-f32v-vf79-p29q
Release Date: 2022-04-26
Fix Resolution: 17.0.1
Step up your Open Source Security Game with Mend here