VDB
Sign up
MEDIUM5.0

GHSA-4f53-xh3v-g8x4

Keycloak secondary factor bypass in step-up authentication

Quick fix

GHSA-4f53-xh3v-g8x4 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>22.0.10</version> for org.keycloak:keycloak-services

Details

Keycloak does not correctly validate its client step-up authentication. A password-authed attacker could use this flaw to register a false second auth factor, alongside the existing one, to a targeted account. The second factor then permits step-up authentication.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 22.0.10
Fix# pom.xml: bump <version>22.0.10</version> for org.keycloak:keycloak-services
Maven/org.keycloak:keycloak-services
Introduced in: 23.0.0Fixed in: 24.0.3
Fix# pom.xml: bump <version>24.0.3</version> for org.keycloak:keycloak-services

References