Vulnerability CVE-2022-1466


Published: 2022-04-26

Description:
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

 References:
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt
https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076
https://bugzilla.redhat.com/show_bug.cgi?id=2050228

Copyright 2026, cxsecurity.com

 

Back to Top