Improper Authorization in Keycloak
Description
Reviewed
Jan 4, 2022
Published to the GitHub Advisory Database
Jan 6, 2022
Published by the National Vulnerability Database
Jan 25, 2022
Last updated
Feb 3, 2023
A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.
References