Critical severity9.8NVD Advisory· Published Jul 8, 2022· Updated Jun 17, 2026
CVE-2022-1245
CVE-2022-1245
Description
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 18.0.0 | 18.0.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-75p6-52g3-rqc8ghsaADVISORY
- github.com/keycloak/keycloak/security/advisories/GHSA-75p6-52g3-rqc8nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-1245ghsaADVISORY
- github.com/keycloak/keycloak/commit/76d83f46fad94ebcbedaa49e6daad458e2894e52ghsaWEB
News mentions
0No linked articles in our index yet.