VDB

RHSA-2022%3A1713

RHSA-2022%3A1713 PUBLISHED CVSS 8 HIGH

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrh-sso-7/sso75-openshift-rhel8@sha256:783e96e2d9fbce3aac018e506486a00709527b496214e6c25eaf4263f0cde8e4_amd64 as a component of Middleware Containers for OpenShiftrh-sso-7/sso75-openshift-rhel8@sha256:783e96e2d9fbce3aac018e506486a00709527b496214e6c25eaf4263f0cde8e4_amd64
Red Hatrh-sso-7/sso75-openshift-rhel8@sha256:4ecf45477860c7980101a1e751522c1b3814088a37d152aa5991536430cdeb4f_ppc64le as a component of Middleware Containers for OpenShift*
Red Hatrh-sso-7/sso7-rhel8-operator-bundle@sha256:1146766ce249aac1b2e06f5c7098ac6a5e76b158ac18c5c39d4898b21c119639_amd64 as a component of Middleware Containers for OpenShiftrh-sso-7/sso7-rhel8-operator-bundle@sha256:1146766ce249aac1b2e06f5c7098ac6a5e76b158ac18c5c39d4898b21c119639_amd64
Red Hatrh-sso-7/sso75-openshift-rhel8@sha256:8b404bb37d4552aeb78ec9d53ef3421c8fe3a6a8bf405c28c5ede8c88087dca1_s390x as a component of Middleware Containers for OpenShiftrh-sso-7/sso75-openshift-rhel8@sha256:8b404bb37d4552aeb78ec9d53ef3421c8fe3a6a8bf405c28c5ede8c88087dca1_s390x

Timeline

  • May 4, 2022 CVE Published
  • Apr 23, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›