Description
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=2050228
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt
https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076
Related Vulnerabilities
CVE-2023-30532 Vulnerability in maven package org.jenkinsci.plugins.spoonscript:spoonscript
CVE-2017-12647 Vulnerability in maven package com.liferay:com.liferay.knowledge.base.service
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:react-admin
CVE-2022-24066 Vulnerability in npm package simple-git
CVE-2022-45398 Vulnerability in maven package org.zeroturnaround:cluster-stats