26.7.3
12 years ago
2 days ago
Known vulnerabilities in the org.keycloak:keycloak-services package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the generic identity-provider creation and update paths in How to fix Missing Authorization? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Replay Attack through IdP-initiated broker logins in the How to fix Replay Attack? A fix was pushed into the | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Access Control Bypass through the Client-Initiated Backchannel Authentication token redemption handler in the How to fix Access Control Bypass? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the OIDC token introspection endpoint in the How to fix Missing Authorization? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the backchannel logout endpoint of the How to fix Improper Verification of Cryptographic Signature? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input in the identity provider update flow for OIDC identity providers. An attacker can capture the existing client secret by sending an update as a delegated administrator that reuses the masked client secret sentinel value while changing security-sensitive settings such as the token URL.
The vulnerable code path manages identity provider configuration updates in How to fix Improper Validation of Consistency within Input? There is no fixed version for | [2.4.0.CR1,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to DNS Rebinding in the client host restriction logic. An attacker can bypass wildcard domain restrictions on client registration or updates by controlling the reverse DNS for their connection and presenting a hostname that merely ends with the configured suffix, such as How to fix DNS Rebinding? There is no fixed version for | [12.0.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard through the How to fix Improperly Implemented Security Check for Standard? There is no fixed version for | [26.7.0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Improper Validation of Consistency within Input due to improper validation of the Note: This is only exploitable if the OIDC identity provider is configured with How to fix Improper Validation of Consistency within Input? There is no fixed version for | [0,) |
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Incorrect Privilege Assignment in the How to fix Incorrect Privilege Assignment? There is no fixed version for | [0,) |