Description
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=2050228
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt
https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076
Related Vulnerabilities
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2022-4742 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2019-20364 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2022-29546 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml
CVE-2023-46234 Vulnerability in maven package org.webjars.npm:browserify-sign