26.7.1
9 years ago
11 days ago
Known vulnerabilities in the org.keycloak:keycloak-server-spi-private package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization in the How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure through the Notes
How to fix Information Exposure? A fix was pushed into the | [0,) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the group retrieval due to an improper conditional check that fails to apply permission filters when FGAP v2 is enabled. An attacker can access sensitive group metadata and attributes by querying child groups through a parent group endpoint without having the necessary per-child view permissions. Note: This is only exploitable if the attacker possesses a delegated administrator role with specific permissions. How to fix Insufficient Granularity of Access Control? Upgrade | [0,26.7.1) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the How to fix Insufficient Granularity of Access Control? Upgrade | [,26.6.3) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Authorization via the user-facing APIs when the Organizations feature is disabled. An attacker can access organization membership data and obtain tokens containing organization claims by making authenticated requests, even after an administrator has disabled the feature at the realm level. How to fix Incorrect Authorization? Upgrade | [,26.6.3) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Replay Attack through the Notes
How to fix Replay Attack? Upgrade | [,26.6.2) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness via the SAML Identity Provider authentication process when it is disabled. An attacker can gain unauthorized access by exploiting the ability to authenticate through a provider that should not be available. How to fix Authentication Bypass by Primary Weakness? Upgrade | [,26.2.14)[26.3.0,26.4.10)[26.5.0,26.5.5) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [,26.2.14)[26.3.0,26.4.10)[26.5.0,26.5.5) |