Skip to content

Incorrect authorization allows unpriviledged users to create other users

High
stianst published GHSA-83x4-9cwr-5487 Dec 20, 2021

Package

keycloak-services (Java)

Affected versions

< 16.0.0

Patched versions

16.0.0

Description

A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.

Severity

High

CVE ID

CVE-2021-4133

Weaknesses