Red Hat Build of Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*
A vulnerability exists in Keycloak's SingleUseObjectProvider, which serves as a global key-value store. This flaw arises from inadequate type and namespace isolation, enabling an unauthenticated attacker to forge authorization codes. Exploiting this vulnerability can result in the creation of access tokens with administrative privileges, leading to unauthorized privilege escalation.
Exploitation of this vulnerability allows for privilege escalation by forging authorization codes and obtaining admin-capable access tokens.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.