Improper access control in Keycloak - CVE-2021-4133
Published: December 22, 2021
Keycloak
Keycloak
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the administrative REST API. A remote user can bypass implemented security restrictions and create new default user accounts, even when new user registration is disabled.