org.keycloak:keycloak-services@26.7.0

  • latest version

    26.7.0

  • first published

    12 years ago

  • latest version published

    20 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.keycloak:keycloak-services package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Validation of Consistency within Input

    org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

    Affected versions of this package are vulnerable to Improper Validation of Consistency within Input due to improper validation of the email_verified claim in the OIDC authentication. An attacker can cause arbitrary email addresses to be marked as verified by configuring a malicious or compromised upstream identity provider and exploiting the lack of correlation between the id_token and the userinfo endpoint responses.

    Note: This is only exploitable if the OIDC identity provider is configured with trustEmail set to true and the userinfo endpoint is enabled.

    How to fix Improper Validation of Consistency within Input?

    There is no fixed version for org.keycloak:keycloak-services.

    [0,)
    • M
    Incorrect Authorization

    org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

    Affected versions of this package are vulnerable to Incorrect Authorization via the ClientResource component in the admin REST API when Fine-Grained Admin Permissions (FGAP) v2 is enabled. An attacker can modify the contents of issued tokens and inject unauthorized data or permissions by bypassing authorization checks on client scope assignments.

    Note: This is only exploitable if the attacker holds a delegated administrator role with specific client management permissions and possesses knowledge of internal resource identifiers (UUIDs).

    How to fix Incorrect Authorization?

    There is no fixed version for org.keycloak:keycloak-services.

    [0,)
    • L
    Incorrect Authorization

    org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

    Affected versions of this package are vulnerable to Incorrect Authorization in the RoleContainerResource process when FGAP v2 is enabled. An attacker can access unauthorized group metadata by enumerating role-to-group mappings if they possess a delegated administrative role with specific view permissions.

    Note: This is only exploitable if the attacker already has a delegated administrative role with view permissions for roles but not for all groups.

    How to fix Incorrect Authorization?

    There is no fixed version for org.keycloak:keycloak-services.

    [0,)
    • H
    Incorrect Privilege Assignment

    org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

    Affected versions of this package are vulnerable to Incorrect Privilege Assignment in the Identity Provider mapper process. An attacker can gain unauthorized administrative privileges by creating a hardcoded role mapping that assigns elevated roles to themselves or others, thereby bypassing intended authorization checks.

    How to fix Incorrect Privilege Assignment?

    There is no fixed version for org.keycloak:keycloak-services.

    [0,)
    • H
    Improper Verification of Cryptographic Signature

    org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

    Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the JWT Authorization Grant flow due to algorithm confusion in signature verification. An attacker can gain unauthorized access and potentially escalate privileges by forging assertions and creating unauthorized access tokens.

    How to fix Improper Verification of Cryptographic Signature?

    A fix was pushed into the master branch but not yet published.

    [0,)
    • H
    Improper Verification of Cryptographic Signature

    org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

    Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the requestObjectSignatureAlg policy bypass during the processing of JWE-encrypted request objects containing raw JSON plaintext. An attacker can submit unauthorized claims by crafting specially formed JWE-encrypted request objects, potentially compromising data integrity within the OpenID Connect authorization flow.

    How to fix Improper Verification of Cryptographic Signature?

    There is no fixed version for org.keycloak:keycloak-services.

    [0,)