RHSA-2021:5217HighCVSS 8.3

Red Hat Security Advisory: Red Hat Single Sign-On 7.5.0 security update

Published
December 20, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2021-4133 — Keycloak: Incorrect authorization allows unpriviledged users to create other users

🎯 Affected products1

  • RHSSO 7.5 async for CVE-2021-4133

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Access to the user-creation functionality in the REST endpoint can be deactivated using CLI commands in undertow. run: bin/jboss-cli.sh --connect /subsystem=undertow/configuration=filter/expression-filter=keycloakPathOverrideUsersCreateEndpoint:add( \ expression="(regex('^/auth/admin/realms/(.*)/users$') and method(POST))-> response-code(400)" \ ) /subsystem=undertow/server=default-server/host=default-host/filter-ref=keycloakPathOverrideUsersCreateEndpoint:add()

🔗 References (6)