Description
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1905089
Related Vulnerabilities
CVE-2022-39353 Vulnerability in npm package @xmldom/xmldom
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2021-21607 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-3632 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2022-1415 Vulnerability in maven package org.drools:drools-compiler