26.7.1
12 years ago
8 days ago
Known vulnerabilities in the org.keycloak:keycloak-services package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key through the How to fix Authorization Bypass Through User-Controlled Key? A fix was pushed into the | [12.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the How to fix Missing Authorization? There is no fixed version for | [9.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Access Control Bypass through the Client-Initiated Backchannel Authentication token redemption handler in the How to fix Access Control Bypass? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Reliance on Untrusted Inputs in a Security Decision through the client authentication flow in the client policies and assertion handling components. An attacker can authenticate with weaker client credentials by supplying a fake unsigned assertion header that makes the server believe the policy requirements have been satisfied. This defeats administrator-mandated requirements for signed JWT assertions and lets a client complete authentication with a simpler method such as a client secret, weakening client authentication controls. How to fix Reliance on Untrusted Inputs in a Security Decision? There is no fixed version for | [13.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure due to insufficient group-permission filtering in This exposes the names, paths, and identifiers of default groups that should remain hidden, revealing internal organizational structure to users who do not have permission to view those groups. Notes
How to fix Information Exposure? A fix was pushed into the | [14.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the Google token exchange flow in the Google Identity Provider token exchange process. An attacker can gain access to a Keycloak realm by supplying a valid Google token from a non-approved Google Workspace domain and exchanging it for a Keycloak token. The issue affects deployments that rely on Google domain restrictions to limit which accounts may sign in, allowing users from disallowed domains to authenticate successfully. How to fix Missing Authorization? There is no fixed version for | [3.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization in the admin REST API through the How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Authentication through the Microsoft account token exchange flow in the Microsoft identity provider component. An attacker can gain unauthorized access to a Keycloak realm by supplying a valid Microsoft token from a different organization and exchanging it. This bypasses the tenant restriction intended to limit logins to a specific Microsoft organization, allowing access to sensitive data and unauthorized actions in deployments that rely on that restriction. How to fix Improper Authentication? There is no fixed version for | [3.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization in the How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization due to the full-scope-disabled client-policy executor. An attacker can create a client with full scope access by omitting the How to fix Missing Authorization? There is no fixed version for | [14.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') in How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | [,26.4.14)[26.6.0,26.6.5)[26.7.0,26.7.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature during identity provider metadata import. An attacker can forge a SAML response and gain unauthorized access to a user account by importing metadata that includes a signing certificate but omits the key How to fix Improper Verification of Cryptographic Signature? Upgrade | [,26.4.14)[26.6.0,26.6.5)[26.7.0,26.7.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure through the How to fix Information Exposure? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the OIDC token introspection endpoint in the How to fix Missing Authorization? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the backchannel logout endpoint of the How to fix Improper Verification of Cryptographic Signature? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure through the Notes
How to fix Information Exposure? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input in the identity provider update flow for OIDC identity providers. An attacker can capture the existing client secret by sending an update as a delegated administrator that reuses the masked client secret sentinel value while changing security-sensitive settings such as the token URL.
The vulnerable code path manages identity provider configuration updates in How to fix Improper Validation of Consistency within Input? There is no fixed version for | [2.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to DNS Rebinding in the client host restriction logic. An attacker can bypass wildcard domain restrictions on client registration or updates by controlling the reverse DNS for their connection and presenting a hostname that merely ends with the configured suffix, such as How to fix DNS Rebinding? There is no fixed version for | [12.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key due to the OAuth 2.0 authorization code handling. An attacker can obtain access tokens for a victim’s identity by intercepting an authorization code and redeeming it with their own client. The affected code path does not bind the authorization code to the client that originally requested it, so a stolen code can be substituted during token exchange and used to log in as the victim. How to fix Authorization Bypass Through User-Controlled Key? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input due to improper validation of the Note: This is only exploitable if the OIDC identity provider is configured with How to fix Improper Validation of Consistency within Input? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Authorization via the Note: This is only exploitable if the attacker holds a delegated administrator role with specific client management permissions and possesses knowledge of internal resource identifiers (UUIDs). How to fix Incorrect Authorization? Upgrade | [0,26.7.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Authorization in the Note: This is only exploitable if the attacker already has a delegated administrative role with view permissions for roles but not for all groups. How to fix Incorrect Authorization? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [,26.4.13)[26.5.0,26.6.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,26.4.13)[26.5.0,26.6.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Session Expiration via the How to fix Insufficient Session Expiration? Upgrade | [,26.4.13)[26.5.0,26.6.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the client URI validation process. An attacker can execute arbitrary scripts in the context of the application by registering a malicious client with a specially crafted redirect URI using mixed-case How to fix Cross-site Scripting (XSS)? Upgrade | [,26.4.13)[26.5.0,26.6.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Privilege Assignment in the How to fix Incorrect Privilege Assignment? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the JWT Authorization Grant flow due to algorithm confusion in signature verification. An attacker can gain unauthorized access and potentially escalate privileges by forging assertions and creating unauthorized access tokens. How to fix Improper Verification of Cryptographic Signature? Upgrade | [,26.6.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the How to fix Insufficient Granularity of Access Control? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure via the How to fix Information Exposure? Upgrade | [2.0.0.Final,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input in the How to fix Improper Validation of Specified Quantity in Input? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Privilege Assignment via improper enforcement of scope mapping in the Fine-Grained Admin Permissions (FGAPv2) feature due to How to fix Incorrect Privilege Assignment? Upgrade | [26.2.0,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input via the authentication process when a client is configured with a wildcard redirect URI. An attacker can cause the client application to incorrectly process attacker-controlled OIDC response parameters by crafting a malicious authorization URL and tricking a user into clicking it. How to fix Improper Validation of Consistency within Input? Upgrade | [0,26.7.0) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the How to fix Improper Verification of Cryptographic Signature? Upgrade | [0,26.7.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Session Expiration due to the How to fix Insufficient Session Expiration? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness via the Client-Initiated Backchannel Authentication (CIBA) flow. An attacker can continue authentication attempts and obtain tokens by exploiting the CIBA flow even when a user account is locked due to brute-force protection. This is only exploitable if CIBA is explicitly enabled and configured, and the user approves the authentication request on their device. How to fix Authentication Bypass by Primary Weakness? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Out-of-bounds Read via the authorization header parsing in the How to fix Out-of-bounds Read? Upgrade | [9.0.0,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in the role rename endpoint. An attacker can gain unauthorized administrative privileges by exploiting a timing window between permission checks and their enforcement. The attacker can escalate their access to realm-wide administrative control, even after their original permissions are revoked and across system reboots. How to fix Time-of-check Time-of-use (TOCTOU) Race Condition? Upgrade | [0,26.7.0) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Authorization via the user-facing APIs when the Organizations feature is disabled. An attacker can access organization membership data and obtain tokens containing organization claims by making authenticated requests, even after an administrator has disabled the feature at the realm level. How to fix Incorrect Authorization? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges in the How to fix Improper Handling of Insufficient Permissions or Privileges? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm through the How to fix Incorrect Implementation of Authentication Algorithm? Upgrade | [9.0.0,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Client-Side Enforcement of Server-Side Security through the How to fix Client-Side Enforcement of Server-Side Security? Upgrade | [9.0.2,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to User Impersonation through the Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central How to fix User Impersonation? Upgrade | [4.0.0.Beta1,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Open Redirect through the Notes
How to fix Open Redirect? Upgrade | [,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Open Redirect via the Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central How to fix Open Redirect? Upgrade | [,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to External Control of Assumed-Immutable Web Parameter via the Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central How to fix External Control of Assumed-Immutable Web Parameter? Upgrade | [26.3.0,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Replay Attack through the Notes
How to fix Replay Attack? Upgrade | [,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [2.0.0.CR1,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Granularity of Access Control via the Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central How to fix Insufficient Granularity of Access Control? Upgrade | [7.0.0,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central. How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the cross-session email verification process. An attacker can gain persistent access to another user's local account by consuming the verification proof when controlling an upstream identity provider account that shares an email address with the victim. This is only exploitable if the attacker controls an upstream identity provider account with the same email as the victim, the victim is actively linking their account, email verification is enabled, and the identity provider is configured with How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [26.3.0,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Certificate Validation via packed self-attestation in The attack surface is limited, as project maintainers note: "By default, for a simple implementation, attestation and AAGUIDs may not be considered necessary." How to fix Improper Certificate Validation? Upgrade | [,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Forced Browsing via the How to fix Forced Browsing? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Origin Validation Error in the UMA token endpoint when the Note: This is only exploitable if the target client is misconfigured with How to fix Origin Validation Error? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Excessive Platform Resource Consumption within a Loop via the How to fix Excessive Platform Resource Consumption within a Loop? Upgrade | [,26.5.7) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization due to improper type and namespace isolation in the How to fix Improper Isolation or Compartmentalization? Upgrade | [,26.5.7) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Open Redirect via improper validation of redirect URIs in the authentication endpoint. An attacker can gain unauthorized access to sensitive information by exploiting path traversal sequences in the redirect parameter, potentially leading to the theft of access tokens. How to fix Open Redirect? Upgrade | [,26.5.7) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Behavior Order: Authorization Before Parsing and Canonicalization via the UMA Policy Resource (user with the How to fix Incorrect Behavior Order: Authorization Before Parsing and Canonicalization? Upgrade | [,26.5.7) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization through improper handling of single-use entries in the How to fix Improper Isolation or Compartmentalization? Upgrade | [,26.5.7) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the How to fix Server-side Request Forgery (SSRF)? Upgrade | [,26.6.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure in the identity-first login flow when Organizations are enabled. An attacker can obtain information about the existence of users by analyzing differential error messages. How to fix Information Exposure? Upgrade | [,26.6.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Access Control Bypass due to incomplete enforcement of access control checks on PUT operations to the How to fix Access Control Bypass? Upgrade | [,26.6.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) when processing client configuration requests. An attacker can make unintended requests to internal or restricted resources by sending a malicious How to fix Server-side Request Forgery (SSRF)? Upgrade | [,26.6.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input via improper validation of encrypted SAML assertions. An attacker can gain unauthorized access by submitting specially crafted SAML assertions. How to fix Improper Validation of Specified Type of Input? Upgrade | [,26.2.14)[26.3.0,26.4.10)[26.5.0,26.5.5) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness via the SAML Identity Provider authentication process when it is disabled. An attacker can gain unauthorized access by exploiting the ability to authenticate through a provider that should not be available. How to fix Authentication Bypass by Primary Weakness? Upgrade | [,26.2.14)[26.3.0,26.4.10)[26.5.0,26.5.5) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [,26.2.14)[26.3.0,26.4.10)[26.5.0,26.5.5) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness when a disabled SAML client is configured as an Identity Provider (IdP)-initiated broker landing target. An attacker can gain unauthorized access to other enabled clients via a Single Sign-On (SSO) session. How to fix Authentication Bypass by Primary Weakness? Upgrade | [,26.2.14)[26.3.0,26.4.10)[26.5.0,26.5.5) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Critical Step in Authentication due to insufficient validation of the authentication Level of Assurance in the Account REST API. An attacker can gain control over a victim's account by deleting the victim's registered MFA device and registering their own, provided they have obtained the victim's primary credentials. How to fix Missing Critical Step in Authentication? Upgrade | [,26.5.7) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges via improper enforcement of roles in the UMA 2.0 Protection API which fails to enforce the How to fix Improper Handling of Insufficient Permissions or Privileges? Upgrade | [,26.4.11)[26.5.0,26.5.6) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Privilege Assignment via the How to fix Incorrect Privilege Assignment? Upgrade | [0,26.5.6) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Authorization in the How to fix Improper Authorization? Upgrade | [0,26.5.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade | [1.9.0.CR1,26.5.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the Admin API when the Organizations feature is enabled. An authenticated attacker can enumerate the organization memberships of any other user if their unique identifier (UUID) is known. Note: This is only exploitable if the Organizations feature is enabled (which is the default in recent versions), the attacker possesses a valid access token for the realm and the attacker knows the UUID of the victim user. How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [0,26.5.6) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the invitation tokens in the registration process. An attacker can gain unauthorized access to organizations by modifying the organization ID and target email within a legitimate invitation token's JWT payload. How to fix Improper Verification of Cryptographic Signature? Upgrade | [,26.5.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard due to improper verification if an Identity Provider (IdP) is enabled before issuing tokens. An attacker can gain unauthorized access by issuing valid access tokens using a disabled Identity Provider's signing key. How to fix Improperly Implemented Security Check for Standard? Upgrade | [,26.5.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Privilege Assignment due to insufficient ownership verification in the UserManagedPermissionService (UMA Protection API). An attacker can gain unauthorized access to modify or delete authorization rules for resources they do not own by updating or deleting a policy associated with multiple resources, where the authorization check only validates ownership of the first resource in the list. How to fix Incorrect Privilege Assignment? Upgrade | [,26.5.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Enforcement of Behavioral Workflow via the Token Exchange implementation. An attacker can obtain access and refresh tokens for users who have been disabled by invoking the token exchange flow with a privileged client, potentially resulting in unauthorized access to previously revoked privileges. How to fix Improper Enforcement of Behavioral Workflow? Upgrade | [,26.5.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition via the How to fix Time-of-check Time-of-use (TOCTOU) Race Condition? Upgrade | [,26.4.11)[26.5.0,26.5.6) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing XML Validation of the How to fix Missing XML Validation? Upgrade | [0,26.5.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Behavior Order: Authorization Before Parsing and Canonicalization due to the How to fix Incorrect Behavior Order: Authorization Before Parsing and Canonicalization? Upgrade | [9.0.0,26.5.4) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authentication Bypass by Alternate Name via the How to fix Authentication Bypass by Alternate Name? Upgrade | [0,26.5.6) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Access Control Bypass via the How to fix Access Control Bypass? Upgrade | [0,26.5.0) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Critical Step in Authentication in the WebAuthn Attestation Statement verification. An attacker can influence policy enforcement by manipulating the registration flow or using a rogue authenticator under user control. How to fix Missing Critical Step in Authentication? Upgrade | [0,26.5.1) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to CRLF Injection during the e-mail registration. An attacker can cause the system to send unsolicited emails limited to 64 characters by injecting special characters into the email input field. How to fix CRLF Injection? Upgrade | [,26.3.3) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insufficient Session Expiration in the "Remember Me" realm setting. An attacker with a long-lived "Remember Me" session (e.g., stole the identity cookie) can maintain access for the full original remember-me lifetime to gain unauthorized access to sensitive information or perform actions as another user. How to fix Insufficient Session Expiration? Upgrade | [,26.4.2) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere via the Note: Direct access to this endpoint returns a 401 Unauthorized error. How to fix Exposure of Sensitive System Information to an Unauthorized Control Sphere? Upgrade | [0,26.4.0) |