26.7.2
12 years ago
1 days ago
Known vulnerabilities in the org.keycloak:keycloak-services package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Authorization due to claim handling in the UMA claim-token evaluation path. An attacker can access protected resources outside the allowed time window by supplying a forged How to fix Incorrect Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the generic identity-provider creation and update paths in How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Replay Attack through IdP-initiated broker logins in the How to fix Replay Attack? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the user creation path in How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key through the How to fix Authorization Bypass Through User-Controlled Key? A fix was pushed into the | [12.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the How to fix Missing Authorization? There is no fixed version for | [9.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Access Control Bypass through the Client-Initiated Backchannel Authentication token redemption handler in the How to fix Access Control Bypass? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Reliance on Untrusted Inputs in a Security Decision through the client authentication flow in the client policies and assertion handling components. An attacker can authenticate with weaker client credentials by supplying a fake unsigned assertion header that makes the server believe the policy requirements have been satisfied. This defeats administrator-mandated requirements for signed JWT assertions and lets a client complete authentication with a simpler method such as a client secret, weakening client authentication controls. How to fix Reliance on Untrusted Inputs in a Security Decision? There is no fixed version for | [13.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure due to insufficient group-permission filtering in This exposes the names, paths, and identifiers of default groups that should remain hidden, revealing internal organizational structure to users who do not have permission to view those groups. Notes
How to fix Information Exposure? A fix was pushed into the | [14.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the Google token exchange flow in the Google Identity Provider token exchange process. An attacker can gain access to a Keycloak realm by supplying a valid Google token from a non-approved Google Workspace domain and exchanging it for a Keycloak token. The issue affects deployments that rely on Google domain restrictions to limit which accounts may sign in, allowing users from disallowed domains to authenticate successfully. How to fix Missing Authorization? There is no fixed version for | [3.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization in the admin REST API through the How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Authentication through the Microsoft account token exchange flow in the Microsoft identity provider component. An attacker can gain unauthorized access to a Keycloak realm by supplying a valid Microsoft token from a different organization and exchanging it. This bypasses the tenant restriction intended to limit logins to a specific Microsoft organization, allowing access to sensitive data and unauthorized actions in deployments that rely on that restriction. How to fix Improper Authentication? There is no fixed version for | [3.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization in the How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization due to the full-scope-disabled client-policy executor. An attacker can create a client with full scope access by omitting the How to fix Missing Authorization? There is no fixed version for | [14.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization during client update handling. An attacker can persist a confidential client that does not meet the realm’s authentication requirements by creating a public client and then updating it to a confidential client with weaker authentication, if they have client management permissions. This affects realms that use client policies to enforce authentication hardening on confidential clients, leaving noncompliant clients in place instead of blocking the update. How to fix Missing Authorization? There is no fixed version for | [26.7.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure through the How to fix Information Exposure? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the OIDC token introspection endpoint in the How to fix Missing Authorization? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the backchannel logout endpoint of the How to fix Improper Verification of Cryptographic Signature? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure through the Notes
How to fix Information Exposure? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input in the identity provider update flow for OIDC identity providers. An attacker can capture the existing client secret by sending an update as a delegated administrator that reuses the masked client secret sentinel value while changing security-sensitive settings such as the token URL.
The vulnerable code path manages identity provider configuration updates in How to fix Improper Validation of Consistency within Input? There is no fixed version for | [2.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to DNS Rebinding in the client host restriction logic. An attacker can bypass wildcard domain restrictions on client registration or updates by controlling the reverse DNS for their connection and presenting a hostname that merely ends with the configured suffix, such as How to fix DNS Rebinding? There is no fixed version for | [12.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input during OIDC authentication flow processing. An attacker can inject duplicate security parameters into the login response by supplying a crafted redirect URL with a fragment portion that bypasses the parameter-pollution check. If a client is configured with a wildcard redirect URI and the application trusts the injected values, the attacker can cause session fixation or account confusion, breaking the user’s login session and causing the app to associate the session with the wrong identity or security context. How to fix Improper Validation of Consistency within Input? There is no fixed version for | [26.5.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard through the How to fix Improperly Implemented Security Check for Standard? There is no fixed version for | [26.7.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key due to the OAuth 2.0 authorization code handling. An attacker can obtain access tokens for a victim’s identity by intercepting an authorization code and redeeming it with their own client. The affected code path does not bind the authorization code to the client that originally requested it, so a stolen code can be substituted during token exchange and used to log in as the victim. How to fix Authorization Bypass Through User-Controlled Key? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data through Notes
How to fix Insertion of Sensitive Information Into Sent Data? A fix was pushed into the | [26.5.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input due to improper validation of the Note: This is only exploitable if the OIDC identity provider is configured with How to fix Improper Validation of Consistency within Input? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Authorization in the Note: This is only exploitable if the attacker already has a delegated administrative role with view permissions for roles but not for all groups. How to fix Incorrect Authorization? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Privilege Assignment in the How to fix Incorrect Privilege Assignment? There is no fixed version for | [0,) |