Vulnerability record · CVE-2022-1245 · published 8 July 2022
CVE-2022-1245: Redhat keycloak missing authorization vulnerability
Redhat · Keycloak
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
Description
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/keycloak/keycloak/security/advisories/GHSA-75p6-52g3-rqc8 | Third Party Advisory |
| https://github.com/keycloak/keycloak/security/advisories/GHSA-75p6-52g3-rqc8 | Third Party Advisory |
Track CVE-2022-1245 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1245), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.