VDB
KO
MEDIUM 4.9

GHSA-8hxp-qmph-w5gq

Keycloak Potential Variable Reference in Model Storage Services

Quick fix

GHSA-8hxp-qmph-w5gq — org.keycloak:keycloak-model-storage-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.3.4</version> for org.keycloak:keycloak-model-storage-services

Details

A flaw was found in org.keycloak/keycloak-model-storage-service. The `KeycloakRealmImport` custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for injection attacks when crafted realm documents are processed. An attacker can leverage this to inject malicious content during the realm import procedure. This can lead to unintended consequences within the Keycloak environment.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.keycloak:keycloak-model-storage-services
Introduced in: 0

No fixed version published yet for org.keycloak:keycloak-model-storage-services (maven). Pin to a known-safe version or switch to an alternative.

Maven / org.keycloak:keycloak-model-storage-services
Introduced in: 26.3.0 Fixed in: 26.3.4
Fix # pom.xml: bump <version>26.3.4</version> for org.keycloak:keycloak-model-storage-services

References