Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenRemote has Improper Access Control via updateUserRealmRoles function
Vulnerability Description
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to `master` realm administrator if the attacker controls any user in `master` realm. Version 1.22.1 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Vulnerability Type
访问控制不恰当
Vulnerability Title
OpenRemote 访问控制错误漏洞
Vulnerability Description
OpenRemote是OpenRemote开源的一个开源物联网平台。 OpenRemote 1.22.1之前版本存在访问控制错误漏洞,该漏洞源于具有write:admin权限的用户可以调用Manager API更新其他领域(包括master)的用户Keycloak领域角色,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A