CVE-2021-4133
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- redhat/keycloak
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2033602Issue Tracking, Third Party Advisory
- https://github.com/keycloak/keycloak/issues/9247Third Party Advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-83x4-9cwr-5487Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlNot Applicable
- https://bugzilla.redhat.com/show_bug.cgi?id=2033602Issue Tracking, Third Party Advisory
- https://github.com/keycloak/keycloak/issues/9247Third Party Advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-83x4-9cwr-5487Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.